{"id":"CVE-2026-82556","title":"A vulnerability was found in Forgejo up to 15.0.4","summary":"A vulnerability was found in Forgejo up to 15.0.4. This issue affects the function net.LookupIP of the file services/migrations/allowlist/is_migrate_allowed.go of the component Repository Migration Handler. Performing a manipulation resu…","severity":"medium","cvss":6.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","cwe":["CWE-918"],"published":"2026-08-30","updated":"2026-08-30","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-82556","references":[{"url":"https://codeberg.org/forgejo/forgejo/commit/b313bb83f5ff22bcc0378e0e0ca7bbd58303f168","label":"cna@vuldb.com"},{"url":"https://codeberg.org/forgejo/forgejo/issues/13433","label":"cna@vuldb.com"},{"url":"https://codeberg.org/forgejo/forgejo/pulls/13490","label":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-82556","label":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/891889","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/397072","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/397072/cti","label":"cna@vuldb.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-82556.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-82556"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2526028"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-82556"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-82556"}],"tags":["nvd","csaf","vex","red-hat"],"ingestedAt":"2026-08-31T02:00:57.741Z","epss":0.00214,"epssPercentile":0.11994,"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","affected":["assisted_installer_for_red_hat_openshift_container_platform 2","aws_load_balancer_operator","builds_for_red_hat_openshift","cert_manager_operator_for_red_hat_openshift","compliance_operator","confidential_compute_attestation","cryostat 4","custom_metric_autoscaler_operator_for_red_hat_openshift","deployment_validation_operator","dpu_kit_for_nvidia","exploit_intelligence","external_secrets_operator_for_red_hat_openshift","fence_agents_remediation_operator","file_integrity_operator","gatekeeper 3","logging_subsystem_for_red_hat_openshift","logical_volume_manager_storage","machine_deletion_remediation_operator","migration_toolkit_for_applications 8","migration_toolkit_for_containers","mirror_registry_for_red_hat_openshift 2","multiarch_tuning_operator","multicluster_engine_for_kubernetes","multicluster_global_hub","network_observability_operator","node_healthcheck_operator","node_maintenance_operator","nvidia_gpu_driver_for_rhel_on_openshift","openshift_api_for_data_protection","openshift_developer_tools_and_services","openshift_lightspeed","openshift_pipelines","openshift_serverless","openshift_service_mesh 3","openshift_source_to_image_s2i","power_monitoring_for_red_hat_openshift","3scale_api_management_platform 2","advanced_cluster_management_for_kubernetes 2","advanced_cluster_security 4","amq_clients"],"slug":"CVE-2026-82556","body":"## Overview\n\nA vulnerability was found in Forgejo up to 15.0.4. This issue affects the function net.LookupIP of the file services/migrations/allowlist/is_migrate_allowed.go of the component Repository Migration Handler. Performing a manipulation results in server-side request forgery. The attack can be initiated remotely. The exploit has been made public and could be used. The patch is named b313bb83f5ff22bcc0378e0e0ca7bbd58303f168. It is recommended to apply a patch to fix this issue. The project maintainer explains: \"I don't intend to backport this to v15 or v16 as it is a breaking change.\"\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · updated 2026-09-08 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-82556.json)","depth":"sunlit","depthScore":35,"depthScoreParts":{"impact":34.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}