CVE-2026-22874
published 2026-07-03CVE-2026-22874: Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.
PriorityP354critical9.6CVSS 3.1
AVNACLPRLUINSCCHIHAN
EPSS
0.55%
43.9th percentile
Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| code.gitea.io | gitea | >= 0 < 1.26.3 | 1.26.3 |
| gitea | gitea_open_source_git_server | <= 1.26.2 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://blog.gitea.com/release-of-1.26.3-and-1.26.4/https://github.com/go-gitea/gitea/pull/38059https://github.com/go-gitea/gitea/pull/38173https://github.com/go-gitea/gitea/releases/tag/v1.26.3https://github.com/go-gitea/gitea/security/advisories/GHSA-2r5c-gw76-rh3whttps://github.com/go-gitea/gitea/security/advisories/GHSA-2r5c-gw76-rh3w
2026-07-03
Published