๐Ÿ” CVE Alert

CVE-2026-96400

UNKNOWN 0.0

Gitea migration SSRF to reserved addresses through ALLOWED_DOMAINS

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

With `[migrations] ALLOWED_DOMAINS` set to a matching entry such as `*` or a hostname wildcard, Gitea's migration URL validation could permit reserved and link-local addresses, such as `169.254.169.254`, even when `ALLOW_LOCALNETWORKS = false`. The local-network block list did not cover these ranges, and a hostname matching the allow list was accepted regardless of its resolved address. A user who can start migrations on such an instance could reach these addresses from the Gitea server; the default empty `ALLOWED_DOMAINS` configuration is not affected.

CWE CWE-918
Vendor gitea
Product gitea
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for gitea gitea

Be the first to know when new unknown vulnerabilities affecting gitea gitea are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Gitea / Gitea
0 โ‰ค 1.27.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/go-gitea/gitea/security/advisories/GHSA-54w9-6cc5-9wj9 github.com: https://github.com/go-gitea/gitea/pull/39426 blog.gitea.com: https://blog.gitea.com/release-of-28.0.0/ github.com: https://github.com/go-gitea/gitea/releases/tag/v28.0.0

Credits

๐Ÿ” https://github.com/ihopenre-eng https://github.com/TheFox0x7 https://github.com/silverwind https://github.com/bircni https://github.com/wxiaoguang