Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata (CVE-2026-59765)

0
Medium
Published: 07/21/2026 (07/21/2026, 21:55:31 UTC)
Source: GCVE Database
Product: code.gitea.io/gitea

Description

Gitea versions prior to 1.27.0 contain a server-side request forgery (SSRF) vulnerability that bypasses existing SSRF protections. The issue arises because certain migration and OAuth avatar update code paths use raw http.Get() calls without host-based filtering, allowing attackers to access internal network services, cloud metadata endpoints, and local files via the file:// scheme. Exploitation requires migration permissions or admin-configured OAuth sources. This can lead to theft of sensitive data such as cloud instance metadata and local configuration files containing secrets.

CVSS v4.0

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
Present
Privileges Required
High
User Interaction
None
Vuln. Confidentiality
High
Vuln. Integrity
None
Vuln. Availability
None
Subsq. Confidentiality
High
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N

Affected software

Goghsa
code.gitea.io/gitea
Affected versions
<1.27.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/22/2026, 00:38:36 UTC

Technical Analysis

Gitea's SSRF protection relies on hostmatcher.NewDialContext() to validate resolved IPs at the TCP dial level for webhook and migration clone URLs. However, three code paths in migration asset downloads and OAuth avatar updates use raw http.Get() calls without this filtering, enabling SSRF to internal services and local file reads via the file:// scheme. This vulnerability allows attackers with migration permissions or control over OAuth sources to cause Gitea to fetch internal cloud metadata (e.g., AWS IMDSv1 credentials) or local files (e.g., /etc/gitea/app.ini) and store them as release assets, bypassing the intended SSRF protections.

Potential Impact

An attacker with migration permissions or control over OAuth avatar URLs can exploit this vulnerability to perform SSRF attacks that bypass Gitea's hostmatcher protections. This enables unauthorized reading of internal cloud metadata services (such as AWS or GCP instance metadata endpoints), local files containing sensitive configuration and secrets, and internal network services. The stolen data can be exfiltrated via release assets in the migrated repository or OAuth avatar updates, potentially exposing credentials and secrets critical to the target environment.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict migration permissions to trusted administrators only and carefully review OAuth2 source configurations. Avoid migrating repositories from untrusted sources. Monitor vendor advisories for updates and apply patches once released to ensure hostmatcher filtering is applied consistently to all HTTP requests in migration and OAuth code paths.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-2wm4-vwp6-v7xc
Osv Schema Version
1.4.0
Aliases
["CVE-2026-59765"]
Ecosystems
["Go"]
Database Specific Severity
MODERATE
Cvss Version
4.0

Threat ID: 6a600aa29c2644c7f8fdfcb0

Added to database: 07/22/2026, 00:11:14 UTC

Last enriched: 07/22/2026, 00:38:36 UTC

Last updated: 07/22/2026, 00:38:36 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses