CVE-2026-96400None▾ SunlitWith `[migrations] ALLOWED_DOMAINS` set to a matching entry such as `*` or a hostname wildcard, Gitea's migration URL validation could permit reserved and link-local addresses, such as `169.254.169.254`, even when `ALLOW_LOCALNETWORKS = …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
With [migrations] ALLOWED_DOMAINS set to a matching entry such as * or a hostname wildcard, Gitea's migration URL validation could permit reserved and link-local addresses, such as 169.254.169.254, even when ALLOW_LOCALNETWORKS = false. The local-network block list did not cover these ranges, and a hostname matching the allow list was accepted regardless of its resolved address. A user who can start migrations on such an instance could reach these addresses from the Gitea server; the default empty ALLOWED_DOMAINS configuration is not affected.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-101029NoneGitea's repository migration and pull mirror egress checks could be bypassed with a hostname that returns multiple DNS answers, because the address that was validated was not necessarily the address Git later connected to
CVE-2026-89430NoneGitea validated a push mirror's remote address against the `[migrations]` allow and block lists only when the mirror was created
CVE-2026-104636NoneGitea validated the initial remote URL for push mirrors, wiki remote checks, and fetches of migrated pull request heads, but the subsequent raw Git operations followed HTTP redirects without revalidating the destination
CVE-2026-70357NoneGitea validates a repository migration hostname against its network allow and block lists before invoking Git, but the Git subprocess independently resolves the hostname when connecting
CVE-2026-101027NoneWhen `[migrations] ALLOWED_DOMAINS` was configured, a hostname matching the allow list was accepted without checking its resolved address against the local-network restrictions
CVE-2026-104632NoneGitea Actions blocks the jobs of workflow runs from first-time fork pull request contributors until a maintainer approves the run