CVE-2026-101027None▾ SunlitWhen `[migrations] ALLOWED_DOMAINS` was configured, a hostname matching the allow list was accepted without checking its resolved address against the local-network restrictions. A user who can start repository migrations and control the …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
When [migrations] ALLOWED_DOMAINS was configured, a hostname matching the allow list was accepted without checking its resolved address against the local-network restrictions. A user who can start repository migrations and control the DNS of an allowed hostname could make it resolve to loopback or private addresses and bypass ALLOW_LOCALNETWORKS = false, reaching internal services from the Gitea server. Instances without ALLOWED_DOMAINS configured are not affected by this specific bypass.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-101029NoneGitea's repository migration and pull mirror egress checks could be bypassed with a hostname that returns multiple DNS answers, because the address that was validated was not necessarily the address Git later connected to
CVE-2026-89430NoneGitea validated a push mirror's remote address against the `[migrations]` allow and block lists only when the mirror was created
CVE-2026-104636NoneGitea validated the initial remote URL for push mirrors, wiki remote checks, and fetches of migrated pull request heads, but the subsequent raw Git operations followed HTTP redirects without revalidating the destination
CVE-2026-70357NoneGitea validates a repository migration hostname against its network allow and block lists before invoking Git, but the Git subprocess independently resolves the hostname when connecting
CVE-2026-96400NoneWith `[migrations] ALLOWED_DOMAINS` set to a matching entry such as `*` or a hostname wildcard, Gitea's migration URL validation could permit reserved and link-local addresses, such as `169.254.169.254`, even when `ALLOW_LOCALNETWORKS = …
CVE-2026-104632NoneGitea Actions blocks the jobs of workflow runs from first-time fork pull request contributors until a maintainer approves the run