Executive brief
Gitea, a popular self-hosted Git service, contains a flaw in how it restricts network requests made by its webhook and repository migration features. An attacker with a standard user account can bypass these restrictions to send requests to internal company servers or cloud metadata services that should be private. This could allow the attacker to steal sensitive information, such as cloud credentials or internal data, and view the results directly within the Gitea interface.
Technical details
An incomplete SSRF protection vulnerability exists in Gitea's 'MatchBuiltinExternal' host matcher. The implementation relies on Go's 'net.IP.IsPrivate()' function, which only accounts for RFC 1918 and RFC 4193 address ranges. Consequently, it fails to block other sensitive ranges including CGNAT (100.64.0.0/10), Azure WireServer (168.63.129.16), and various IPv6 transition mechanisms (NAT64, Teredo, 6to4). An authenticated attacker can exploit this via webhooks or repository migrations to perform non-blind SSRF, capturing up to 1 MiB of the response body from internal services. The vulnerability is addressed in version 1.26.3.
Affected products
- Gitea Gitea < 1.26.3
Timeline
- 2026-06-21: advisory: GitHub Advisory published
- 2026-06-21: patched: Fixed in version 1.26.3