Gitea · Gitea · CVE-2026-27779
**Name of the Vulnerable Software and Affected Versions**
Gitea versions prior to 1.25.5
**Description**
The software accepts malformed or injected `forwarded-proto` values during the detection of public URLs. This flaw allows for the generation of spoofed canonical URLs.
**Recommendations**
Update Gitea to version 1.25.5 or later.