Threats Tagged 'cve-2026-57894'
View all threats tagged with 'cve-2026-57894'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-57894'
Click on any threat for detailed analysis and mitigation recommendations
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration (CVE-2026-57894)CVE-2026-57894 0 Gitea versions prior to 1.27.0 contain a vulnerability where repository migration URLs are validated before cloning, but the Git client follows HTTP redirects without restriction. This allows a low-privileged authenticated user to bypass URL allow/block policies by submitting a public Git URL that redirects to an internal or otherwise blocked Git repository. The Git client then fetches repository data from the redirected internal endpoint, enabling exfiltration of internal Git repositories. The issue affects migration and mirror fetch operations, potentially exposing sensitive internal repositories and secrets. The vulnerability is high severity for internet-facing instances with migrations enabled and can escalate to critical if sensitive internal data is exposed. No direct unauthenticated exploitation or remote code execution is confirmed. Join the discussion | GCVE Database | 07/21/2026, 19:17:21 UTC Added: 07/22/2026, 00:11:51 UTC |
Showing 1 to 1 of 1 result