Junglewise Threat Intelligence

CVE-2026-57894: Gitea SSRF and repository exfiltration via Git HTTP redirects

CVE-2026-57894 · Severity: high · CVSS 8.5 · Published 2026-07-21

Technologies: code.gitea.io/gitea (Go), Gitea, gitea.dev (Go). Vendors: Go, Gitea.

Executive brief

A vulnerability in Gitea's repository migration feature allows users to bypass security filters and access internal network resources. By providing a specially crafted URL that redirects to an internal server, an attacker can trick Gitea into stealing private source code or sensitive configuration files from the company's internal network. This could lead to the exposure of trade secrets, login credentials, and other sensitive data stored in private repositories.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in Gitea's repository migration and pull mirror features. While Gitea validates the initial migration URL against an allow/block list, it delegates the actual 'git clone' and 'git fetch' operations to the Git CLI. By default, Git follows HTTP redirects (http.followRedirects=initial), which Gitea does not re-validate. An authenticated attacker can provide a public URL that redirects to an internal Git service (e.g., 127.0.0.1 or internal hostnames). This allows the attacker to import internal repository contents, including history and secrets, into a Gitea repository they control. The issue is fixed in version 1.27.0 by disabling redirect following in Git commands.

Affected products

  • Gitea Gitea < 1.27.0

Timeline

  • 2026-07-13: advisory: Initial GitHub Advisory published
  • 2026-07-21: patched: Version 1.27.0 released

References

Related threats