PT-2026-83623 · Forgejo · Forgejo

·

CVE-2026-82556

·

Published

2026-08-30

·

Updated

2026-08-30

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Forgejo versions 15.0.0 through 15.0.4
Description A server-side request forgery (SSRF) issue exists in the Repository Migration Handler. A remote authenticated user with repository-migration privileges can manipulate the migration destination to abuse the net.LookupIP function within the services/migrations/allowlist/is migrate allowed.go file. This allows the attacker to force the Forgejo server to initiate unintended outbound network requests to internal services, such as internal APIs, CI/CD infrastructure, or cloud-management networks, effectively using the server as a network proxy to bypass security boundaries.
Recommendations Apply patch b313bb83f5ff22bcc0378e0e0ca7bbd58303f168 for versions 15.0.0 through 15.0.4. Restrict repository-migration privileges to minimize the attack surface. Implement network-level egress controls to prevent the application from reaching sensitive management networks, internal APIs, and RFC1918 ranges.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82556

Affected Products

Forgejo