Executive brief
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev
Affected products
- Go code.gitea.io/gitea
- Go gitea.dev
CVE identifiers
- CVE-2026-59765
- CVE-2026-34966
Junglewise Threat Intelligence
CVE-2026-59765 · Severity: low · CVSS 3.1 · Published 2026-07-22
Technologies: code.gitea.io/gitea (Go), gitea.dev (Go). Vendors: Go.
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev