Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Gitea | Gitea Open Source Git Server | >= 0, <= 1.26.2CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.