---
id: CVE-2026-82556
title: A vulnerability was found in Forgejo up to 15.0.4
summary: >-
  A vulnerability was found in Forgejo up to 15.0.4. This issue affects the
  function net.LookupIP of the file
  services/migrations/allowlist/is_migrate_allowed.go of the component
  Repository Migration Handler. Performing a manipulation resu…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-918
published: '2026-08-30'
updated: '2026-08-30'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82556'
references:
  - url: >-
      https://codeberg.org/forgejo/forgejo/commit/b313bb83f5ff22bcc0378e0e0ca7bbd58303f168
    label: cna@vuldb.com
  - url: 'https://codeberg.org/forgejo/forgejo/issues/13433'
    label: cna@vuldb.com
  - url: 'https://codeberg.org/forgejo/forgejo/pulls/13490'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-82556'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/891889'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/397072'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/397072/cti'
    label: cna@vuldb.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-82556.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-82556'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2526028'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-82556'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82556'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
ingestedAt: '2026-08-31T02:00:57.741Z'
epss: 0.00366
epssPercentile: 0.27747
vendor: Red Hat
product: Red Hat Enterprise Linux 10
affected:
  - assisted_installer_for_red_hat_openshift_container_platform 2
  - aws_load_balancer_operator
  - builds_for_red_hat_openshift
  - cert_manager_operator_for_red_hat_openshift
  - compliance_operator
  - confidential_compute_attestation
  - cryostat 4
  - custom_metric_autoscaler_operator_for_red_hat_openshift
  - deployment_validation_operator
  - dpu_kit_for_nvidia
  - exploit_intelligence
  - external_secrets_operator_for_red_hat_openshift
  - fence_agents_remediation_operator
  - file_integrity_operator
  - gatekeeper 3
  - logging_subsystem_for_red_hat_openshift
  - logical_volume_manager_storage
  - machine_deletion_remediation_operator
  - migration_toolkit_for_applications 8
  - migration_toolkit_for_containers
  - mirror_registry_for_red_hat_openshift 2
  - multiarch_tuning_operator
  - multicluster_engine_for_kubernetes
  - multicluster_global_hub
  - network_observability_operator
  - node_healthcheck_operator
  - node_maintenance_operator
  - nvidia_gpu_driver_for_rhel_on_openshift
  - openshift_api_for_data_protection
  - openshift_developer_tools_and_services
  - openshift_lightspeed
  - openshift_pipelines
  - openshift_serverless
  - openshift_service_mesh 3
  - openshift_source_to_image_s2i
  - power_monitoring_for_red_hat_openshift
  - 3scale_api_management_platform 2
  - advanced_cluster_management_for_kubernetes 2
  - advanced_cluster_security 4
  - amq_clients
---

## Overview

A vulnerability was found in Forgejo up to 15.0.4. This issue affects the function net.LookupIP of the file services/migrations/allowlist/is_migrate_allowed.go of the component Repository Migration Handler. Performing a manipulation results in server-side request forgery. The attack can be initiated remotely. The exploit has been made public and could be used. The patch is named b313bb83f5ff22bcc0378e0e0ca7bbd58303f168. It is recommended to apply a patch to fix this issue. The project maintainer explains: "I don't intend to backport this to v15 or v16 as it is a breaking change."

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Moderate · updated 2026-09-08 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-82556.json)
