---
id: CVE-2026-25779
title: 'Gitea: Open Redirect via redirect_to'
summary: 'Gitea: Open Redirect via redirect_to'
severity: medium
cwe:
  - CWE-601
vendor: go-gitea
product: github.com/go-gitea/gitea
ecosystem: go
affected:
  - github.com/go-gitea/gitea <= 1.25.4
patched:
  - github.com/go-gitea/gitea 1.26.0
published: '2026-06-17'
updated: '2026-06-17'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-j5r2-4c8j-xc3m'
references:
  - url: 'https://github.com/go-gitea/gitea/security/advisories/GHSA-j5r2-4c8j-xc3m'
  - url: 'https://github.com/advisories/GHSA-j5r2-4c8j-xc3m'
tags:
  - ghsa
  - go
ingestedAt: '2026-06-29T14:31:47.222Z'
epss: 0.00344
epssPercentile: 0.28014
---

## Overview

### Details

Despite the validation within `urlIsRelative` in `modules/httplib/url.go`, an open redirect is still possible due to usage of directory traversal sequences plus a back-slash in the "redirect_to" parameter.

### PoC

When a user uses this URL to login:

`https://gitea.com/user/login?redirect_to=/a/../\example.com`

They would be redirected to `example.com` upon a successful login to their gitea account.

### Impact

* Phishing: Attackers can use trusted domain links to redirect victims to credential-harvesting pages
* OAuth/SSO Token Theft: In authentication flows, authorization codes or tokens may leak via redirect
* Referer Leakage: Sensitive URL parameters may be exposed to attacker domains via the Referer header
* Cache Poisoning: In deployments with shared caches, malicious redirects may be cached and served to other users

## Affected packages

- `github.com/go-gitea/gitea <= 1.25.4`

## Remediation

Upgrade to a patched release:

- `github.com/go-gitea/gitea 1.26.0`
