PT-2026-107129 · Gitea · Gitea
CVE-2026-101027
·
Published
2026-10-06
·
Updated
2026-10-07
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Gitea (affected versions not specified)
Description
A flaw exists when the
[migrations] ALLOWED DOMAINS configuration is active. The system accepts hostnames matching the allow list without verifying if the resolved address violates local-network restrictions. An attacker capable of initiating repository migrations and controlling the DNS of an allowed hostname can force it to resolve to loopback or private addresses. This allows the bypass of the ALLOW LOCALNETWORKS = false setting, enabling the Gitea server to reach internal services.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gitea