VYPR
Unrated severityNVD Advisory· Published Oct 6, 2026

CVE-2026-101027

CVE-2026-101027

Description

When [migrations] ALLOWED_DOMAINS was configured, a hostname matching the allow list was accepted without checking its resolved address against the local-network restrictions. A user who can start repository migrations and control the DNS of an allowed hostname could make it resolve to loopback or private addresses and bypass ALLOW_LOCALNETWORKS = false, reaching internal services from the Gitea server. Instances without ALLOWED_DOMAINS configured are not affected by this specific bypass.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.