Moderate severityNVD Advisory· Published Jun 17, 2026· Updated Jun 17, 2026
Gitea: Open Redirect via redirect_to
CVE-2026-25779
Description
Details
Despite the validation within urlIsRelative in modules/httplib/url.go, an open redirect is still possible due to usage of directory traversal sequences plus a back-slash in the "redirect_to" parameter.
PoC
When a user uses this URL to login:
https://gitea.com/user/login?redirect_to=/a/../\example.com
They would be redirected to example.com upon a successful login to their gitea account.
Impact
- Phishing: Attackers can use trusted domain links to redirect victims to credential-harvesting pages
- OAuth/SSO Token Theft: In authentication flows, authorization codes or tokens may leak via redirect
- Referer Leakage: Sensitive URL parameters may be exposed to attacker domains via the Referer header
- Cache Poisoning: In deployments with shared caches, malicious redirects may be cached and served to other users
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/go-gitea/giteaGo | < 1.26.0 | 1.26.0 |
Affected products
2Patches
Vulnerability mechanics
References
2News mentions
1- Gitea: Ten CVEs Disclosed Together, Seven High-Severity Token-Scope and Auth Bypass FlawsVypr Intelligence · Jun 17, 2026