PT-2026-107129 · Gitea · Gitea

CVE-2026-101027

·

Published

2026-10-06

·

Updated

2026-10-07

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Gitea (affected versions not specified)
Description A flaw exists when the [migrations] ALLOWED DOMAINS configuration is active. The system accepts hostnames matching the allow list without verifying if the resolved address violates local-network restrictions. An attacker capable of initiating repository migrations and controlling the DNS of an allowed hostname can force it to resolve to loopback or private addresses. This allows the bypass of the ALLOW LOCALNETWORKS = false setting, enabling the Gitea server to reach internal services.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101027
GHSA-FQJR-23C8-GG9M

Affected Products

Gitea