Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Oct 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 07 Oct 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gitea
Gitea gitea |
|
| Vendors & Products |
Gitea
Gitea gitea |
Tue, 06 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | With `[migrations] ALLOWED_DOMAINS` set to a matching entry such as `*` or a hostname wildcard, Gitea's migration URL validation could permit reserved and link-local addresses, such as `169.254.169.254`, even when `ALLOW_LOCALNETWORKS = false`. The local-network block list did not cover these ranges, and a hostname matching the allow list was accepted regardless of its resolved address. A user who can start migrations on such an instance could reach these addresses from the Gitea server; the default empty `ALLOWED_DOMAINS` configuration is not affected. | |
| Title | Gitea migration SSRF to reserved addresses through ALLOWED_DOMAINS | |
| Weaknesses | CWE-918 | |
| References |
|
Status: PUBLISHED
Assigner: Gitea
Published:
Updated: 2026-10-07T11:35:27.280Z
Reserved: 2026-10-04T21:59:53.556Z
Link: CVE-2026-96400
Updated: 2026-10-07T11:35:18.304Z
Status : Awaiting Analysis
Published: 2026-10-06T20:17:35.387
Modified: 2026-10-07T13:45:36.947
Link: CVE-2026-96400
No data.
OpenCVE Enrichment
Updated: 2026-10-07T13:45:06Z
-
CWE-918
Server-Side Request Forgery (SSRF)