VYPR
Unrated severityNVD Advisory· Published Oct 6, 2026

CVE-2026-96400

CVE-2026-96400

Description

With [migrations] ALLOWED_DOMAINS set to a matching entry such as * or a hostname wildcard, Gitea's migration URL validation could permit reserved and link-local addresses, such as 169.254.169.254, even when ALLOW_LOCALNETWORKS = false. The local-network block list did not cover these ranges, and a hostname matching the allow list was accepted regardless of its resolved address. A user who can start migrations on such an instance could reach these addresses from the Gitea server; the default empty ALLOWED_DOMAINS configuration is not affected.

Affected products

2
  • Go Gitea/Giteareferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <28.0.0

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.

CVE-2026-96400 · VYPR