cbcvebase.
CVE-2026-58418
published 2026-07-21

CVE-2026-58418: Gitea: SSRF via HTTP Redirect in Repository Migration ## Summary Gitea 1.25.4 validates the initial URL provided to the repository migration endpoint (`POST…

medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.41%
34.3th percentile
Gitea: SSRF via HTTP Redirect in Repository Migration

## Summary

Gitea 1.25.4 validates the initial URL provided to the repository migration endpoint (`POST /api/v1/repos/migrate`) and correctly blocks requests to internal addresses like `127.0.0.1` or RFC1918 ranges. However, if the initial URL points to an attacker-controlled server that responds with an HTTP 302 redirect to an internal address, Gitea follows the redirect without performing a second validation. This allows a low-privilege user to reach internal services through Gitea as a proxy.

## Affected Version

Gitea 1.25.4 (latest stable at time of writing), default configuration.

## Prerequisites

1. A regular Gitea user account (no admin privileges required)
2. An attacker-controlled server reachable from the internet that serves HTTP 302 redirects

## Reproduction

### Environment

| Role | Location | Network |
|------------------|----------------------------------------------------------------|------------------------------------------|
| Attacker | Any machine with internet access | External network (VLAN A) |
| Gitea Server | Windows 11 VM, Gitea 1.25.4, default config, SQLite | Internal network (VLAN B) |
| Internal service | Same VM, bound to `127.0.0.1:18082` | Localhost only |
| Redirect server | Attacker-controlled public server, port 18080 | Internet |

The attacker can reach Gitea on port 3000 but cannot reach port 18082 on the VM. This was verified by attempting a direct connection, which was refused.

### Step 1: Create an attacker account on Gitea

Register a normal user account on the Gitea instance (or use any existing non-admin account). Then generate an API token under **Settings > Applications** with the `repo: write` scope. The migration endpoint requires this because it creates a new repository. This token is referenced as `` in the steps below.

### Step 2: Set up an internal service on the Gitea host

On the Gitea VM, create a bare Git repository that simulates an internal servic

Affected

1 ranges
VendorProductVersion rangeFixed in
code.gitea.iogitea>= 0 < 1.26.41.26.4
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.