top of page
perceptive_background_267k.jpg

Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fet…

Published:

4 augustus 2026 om 22:00:00

Alert date:

5 augustus 2026 om 22:02:16

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Data Breach & Exfiltration, Identity & Access

Gitea versions prior to 1.27.0 are affected by a server-side request forgery (SSRF) vulnerability that allows authenticated attackers to bypass existing SSRF protections. The flaw exists in HTTP fetch operations within migration and OAuth avatar code paths that use Go's default http.Get without a custom DialContext. Attackers can supply arbitrary URLs through release asset download URLs, pull-request patch URLs, or OAuth avatar endpoints. This can be exploited to reach internal services, cloud instance-metadata endpoints, or read local files including application configuration files containing database credentials and signing secrets. Exfiltrated content can be persisted as migration release assets for later retrieval, making data exfiltration stealthy and persistent. The vulnerability requires authentication but poses a high risk to organizations hosting Gitea internally or in cloud environments. A fix is available in Gitea 1.27.0, and affected users are strongly advised to upgrade immediately.

Technical details

Mitigation steps:

Affected products:

Gitea prior to 1.27.0

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page