Unrated severityNVD Advisory· Published Oct 6, 2026
CVE-2026-101027
CVE-2026-101027
Description
When [migrations] ALLOWED_DOMAINS was configured, a hostname matching the allow list was accepted without checking its resolved address against the local-network restrictions. A user who can start repository migrations and control the DNS of an allowed hostname could make it resolve to loopback or private addresses and bypass ALLOW_LOCALNETWORKS = false, reaching internal services from the Gitea server. Instances without ALLOWED_DOMAINS configured are not affected by this specific bypass.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.