CVE-2026-58418
published 2026-07-21CVE-2026-58418: Gitea: SSRF via HTTP Redirect in Repository Migration ## Summary Gitea 1.25.4 validates the initial URL provided to the repository migration endpoint (`POST…
medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.41%
34.3th percentile
Gitea: SSRF via HTTP Redirect in Repository Migration ## Summary Gitea 1.25.4 validates the initial URL provided to the repository migration endpoint (`POST /api/v1/repos/migrate`) and correctly blocks requests to internal addresses like `127.0.0.1` or RFC1918 ranges. However, if the initial URL points to an attacker-controlled server that responds with an HTTP 302 redirect to an internal address, Gitea follows the redirect without performing a second validation. This allows a low-privilege user to reach internal services through Gitea as a proxy. ## Affected Version Gitea 1.25.4 (latest stable at time of writing), default configuration. ## Prerequisites 1. A regular Gitea user account (no admin privileges required) 2. An attacker-controlled server reachable from the internet that serves HTTP 302 redirects ## Reproduction ### Environment | Role | Location | Network | |------------------|----------------------------------------------------------------|------------------------------------------| | Attacker | Any machine with internet access | External network (VLAN A) | | Gitea Server | Windows 11 VM, Gitea 1.25.4, default config, SQLite | Internal network (VLAN B) | | Internal service | Same VM, bound to `127.0.0.1:18082` | Localhost only | | Redirect server | Attacker-controlled public server, port 18080 | Internet | The attacker can reach Gitea on port 3000 but cannot reach port 18082 on the VM. This was verified by attempting a direct connection, which was refused. ### Step 1: Create an attacker account on Gitea Register a normal user account on the Gitea instance (or use any existing non-admin account). Then generate an API token under **Settings > Applications** with the `repo: write` scope. The migration endpoint requires this because it creates a new repository. This token is referenced as `` in the steps below. ### Step 2: Set up an internal service on the Gitea host On the Gitea VM, create a bare Git repository that simulates an internal servic
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| code.gitea.io | gitea | >= 0 < 1.26.4 | 1.26.4 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-21
Published