CVE-2026-70357
Gitea repository migration SSRF through DNS rebinding
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Gitea validates a repository migration hostname against its network allow and block lists before invoking Git, but the Git subprocess independently resolves the hostname when connecting. An attacker who can start a migration and control the destination's DNS can change the address between validation and connection to reach a blocked internal address. The affected path is the Git clone operation; validation in the migration HTTP client's dialer does not protect the independently connecting Git subprocess.
| CWE | CWE-918 |
| Vendor | gitea |
| Product | gitea |
| Published | Oct 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for gitea gitea
Be the first to know when new unknown vulnerabilities affecting gitea gitea are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Gitea / Gitea
0 โค 1.27.3
References
Credits
๐ https://github.com/tikket1 ๐ https://github.com/SAJ0x00IN https://github.com/vuductruong12 https://github.com/lilmingwa13 ๐ https://github.com/rajivraj ๐ https://github.com/ahmdobeidat https://github.com/TheFox0x7 https://github.com/silverwind https://github.com/bircni https://github.com/wxiaoguang