Gitea 在执行 Git 操作前,会验证仓库迁移的主机名是否在网络允许和阻止列表中。然而,Git 子进程在建立连接时是独立解析该主机名的。如果攻击者能够发起迁移请求并控制目标主机的 DNS 响应,便可以在主机名验证与 Git 实际连接之间篡改 DNS 解析结果,从而绕过访问控制,访问到被阻止的内部地址。受影响的场景是 Git 克隆操作;迁移过程中 HTTP 客户端连接器的验证机制无法保护独立建立连接的 Git 子进程。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-104636 | Gitea SSRF through Git HTTP redirects in mirrors and fetches | |
| CVE-2026-73278 | Gitea WebAuthn bypass during OAuth and OIDC sign-in | |
| CVE-2026-79960 | Gitea deploy key pushes acting as the repository owner | |
| CVE-2026-96580 | Gitea Actions memory exhaustion through large static matrices | |
| CVE-2026-96589 | Gitea private repository access retained after rejected transfer | |
| CVE-2026-96400 | Gitea migration SSRF to reserved addresses through ALLOWED_DOMAINS | |
| CVE-2026-96399 | Gitea denial of service through external issue tracker patterns | |
| CVE-2026-96404 | Gitea installer authentication bypass for existing accounts | |
| CVE-2026-104626 | Gitea fork workflow job revival through later approval | |
| CVE-2026-104632 | Gitea fork workflow approval bypass through cancel and rerun | |
| CVE-2026-94205 | Gitea fork workflow approval bypass through maintainer-triggered events | |
| CVE-2026-101027 | Gitea migration SSRF through ALLOWED_DOMAINS address check bypass | |
| CVE-2026-101029 | Gitea migration and pull mirror SSRF through multi-answer DNS | |
| CVE-2026-95106 | Gitea review and execution mismatch through duplicate tree entries | |
| CVE-2026-95112 | Gitea issue reference parsing CPU exhaustion | |
| CVE-2026-89430 | Gitea push mirror SSRF and forced writes to internal Git hosts | |
| CVE-2026-103504 | Gitea API team demotion not applied to unit permissions | |
| CVE-2026-103667 | Gitea container registry stored XSS through blob media type | |
| CVE-2026-103059 | Gitea built-in SSH server authentication bypass through key case folding | |
| CVE-2026-103670 | Gitea trusted workflow cancellation by unapproved fork runs |
No comments yet