Impact
A server‑side request forgery flaw exists in Gitea 1.26.2, allowing attackers to supply arbitrary URLs that the server will resolve and fetch. Identified as CWE‑918, this flaw can expose internal network resources, read confidential data, or facilitate lateral movement by accessing internal APIs or services that the server can reach. The advisory reports two distinct SSRF paths; once triggered, a malicious actor could retrieve sensitive information from internal endpoints or use the server as a proxy to scan the internal network.
Affected Systems
Gitea Open Source Git Server, version 1.26.2. No other versions are listed as affected in this advisory, so only installations running 1.26.2 are vulnerable.
Risk and Exploitability
No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, so the likelihood of exploitation is uncertain. However, SSRF weaknesses typically allow attackers to reach otherwise inaccessible internal hosts or APIs, and the lack of network segmentation around Gitea could make exploitation straightforward for an authenticated or anonymous attacker.
OpenCVE Enrichment
Github GHSA