VYPR
Unrated severityNVD Advisory· Published Jul 3, 2026· Updated Jul 6, 2026

Gitea forwarded-proto handling allows public URL spoofing

CVE-2026-27779

Description

Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting public URLs, allowing spoofed canonical URL generation.

Affected products

1

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.