Description
Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)
Published: 2026-08-13
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Two SSRF vulnerabilities exist in the migration/mirror functionality of Gitea. An attacker can influence the server to resolve arbitrary DNS names or bypass re-validation, causing Gitea to send requests to internal or external resources on the attacker's behalf. This flaw enables reading or writing data from internal services that the Gitea instance can reach, posing a risk to confidentiality and integrity.

Affected Systems

The product affected is Gitea Open Source Git Server. Any deployment that includes the migration/mirror feature is at risk. Version information is unspecified, but the fix is included in release 1.27.0 and later.

Risk and Exploitability

The vulnerability is identified as a server‑side request forgery with internal network reach. No EPSS score or KEV listing is available. The attack vector likely involves sending injected data through the migration/mirror API or web interface, and authentication may not be required if the endpoint is publicly reachable. Effective risk depends on the exposure of the endpoint and network segmentation.

Generated by OpenCVE AI on August 13, 2026 at 19:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Gitea to version 1.27.0 or later, which contains the SSRF fix.
  • If upgrading is not possible immediately, disable or restrict access to the migration/mirror endpoints so that external actors cannot trigger the vulnerable logic.
  • Configure the network firewall or proxy to block outbound HTTP/HTTPS requests from the Gitea server to internal networks, limiting the potential impact of any SSRF exploitation.

Generated by OpenCVE AI on August 13, 2026 at 19:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Gitea
Gitea gitea Open Source Git Server
Vendors & Products Gitea
Gitea gitea Open Source Git Server

Thu, 13 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)
Title Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)
Weaknesses CWE-284
References

Subscriptions

Gitea Gitea Open Source Git Server
cve-icon MITRE

Status: PUBLISHED

Assigner: Gitea

Published:

Updated: 2026-08-13T16:44:57.726Z

Reserved: 2026-07-08T09:19:08.751Z

Link: CVE-2026-58508

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T17:17:28.757

Modified: 2026-08-13T17:17:28.757

Link: CVE-2026-58508

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T19:30:03Z

Weaknesses