Junglewise Threat Intelligence

CVE-2026-59765: GO-2026-6039 - Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher , Reads Internal Files and Cloud Metadata in gitea.dev

CVE-2026-59765 · Severity: low · CVSS 3.1 · Published 2026-07-22

Technologies: code.gitea.io/gitea (Go), gitea.dev (Go). Vendors: Go.

Executive brief

Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev

Affected products

  • Go code.gitea.io/gitea
  • Go gitea.dev

CVE identifiers

  • CVE-2026-59765
  • CVE-2026-34966

Related threats