Executive brief
Gitea, a popular self-hosted Git service, contains two security flaws that allow attackers to bypass network restrictions. These vulnerabilities enable attackers to force the Gitea server to make requests to internal network services that should be private, potentially exposing sensitive internal data, configuration headers, or allowing for internal port scanning. This could lead to the compromise of internal infrastructure that is not directly accessible from the internet.
Technical details
Two SSRF vulnerabilities were identified in Gitea. First, the 'hostmatcher' component, used for webhooks and repo migrations, fails to block several non-routable address families, most notably CGNAT (100.64.0.0/10). This allows authenticated users to exfiltrate up to 1MB of response data from internal services. Second, the OpenID sign-in endpoint (/user/login/openid) uses a default HTTP client without any IP filtering or CSRF protection, allowing unauthenticated attackers to perform blind SSRF against internal targets. The root cause is a reliance on Go's net.IP.IsPrivate() which does not cover all reserved ranges, and a failure to apply the hostmatcher to the OpenID discovery process. These issues are addressed in version 1.27.0.
Affected products
- Gitea Gitea < 1.27.0
Timeline
- 2026-07-13: advisory: Initial GitHub Advisory published
- 2026-07-21: patched: Updated with patch information for version 1.27.0