当 配置项设置为匹配项(例如 或主机名通配符)时,Gitea 的迁移 URL 验证可能会允许保留地址和链路本地地址(例如 ),即使 (禁止访问本地网络)也未生效。原因是本地网络黑名单未涵盖这些地址范围,并且只要主机名匹配允许列表,无论其解析后的实际 IP 地址如何,都会被接受。因此,具备在该实例上启动迁移任务权限的用户,能够从 Gitea 服务器访问这些受保护的地址。注意:默认情况下 为空,此漏洞不影响默认配置。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-104636 | Gitea SSRF through Git HTTP redirects in mirrors and fetches | |
| CVE-2026-73278 | Gitea WebAuthn bypass during OAuth and OIDC sign-in | |
| CVE-2026-79960 | Gitea deploy key pushes acting as the repository owner | |
| CVE-2026-70357 | Gitea repository migration SSRF through DNS rebinding | |
| CVE-2026-96580 | Gitea Actions memory exhaustion through large static matrices | |
| CVE-2026-96589 | Gitea private repository access retained after rejected transfer | |
| CVE-2026-96399 | Gitea denial of service through external issue tracker patterns | |
| CVE-2026-96404 | Gitea installer authentication bypass for existing accounts | |
| CVE-2026-104626 | Gitea fork workflow job revival through later approval | |
| CVE-2026-104632 | Gitea fork workflow approval bypass through cancel and rerun | |
| CVE-2026-94205 | Gitea fork workflow approval bypass through maintainer-triggered events | |
| CVE-2026-101027 | Gitea migration SSRF through ALLOWED_DOMAINS address check bypass | |
| CVE-2026-101029 | Gitea migration and pull mirror SSRF through multi-answer DNS | |
| CVE-2026-95106 | Gitea review and execution mismatch through duplicate tree entries | |
| CVE-2026-95112 | Gitea issue reference parsing CPU exhaustion | |
| CVE-2026-89430 | Gitea push mirror SSRF and forced writes to internal Git hosts | |
| CVE-2026-103504 | Gitea API team demotion not applied to unit permissions | |
| CVE-2026-103667 | Gitea container registry stored XSS through blob media type | |
| CVE-2026-103059 | Gitea built-in SSH server authentication bypass through key case folding | |
| CVE-2026-103670 | Gitea trusted workflow cancellation by unapproved fork runs |
No comments yet