Unrated severityNVD Advisory· Published Jul 3, 2026· Updated Jul 6, 2026
Gitea forwarded-proto handling allows public URL spoofing
CVE-2026-27779
Description
Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting public URLs, allowing spoofed canonical URL generation.
Affected products
1Patches
Vulnerability mechanics
References
4- github.com/go-gitea/gitea/pull/36810mitrepatch
- github.com/go-gitea/gitea/pull/36836mitrepatch
- blog.gitea.com/release-of-1.25.5/mitrerelease-notes
- github.com/go-gitea/gitea/releases/tag/v1.25.5mitrerelease-notes
News mentions
0No linked articles in our index yet.