CVE-2026-22874 Details
Description
Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.
A vulnerability exists in Gitea versions through 1.26.2, where the default allow-list for webhooks and repository migrations provides incomplete protection against Server-Side Request Forgery (SSRF) attacks. The allow-list, which is intended to filter external hosts, fails to block several IP ranges commonly used for cloud metadata services and internal networks. This flaw allows authenticated users to send HTTP requests to these internal destinations and access the responses via the webhook history interface.
Users are advised to upgrade to Gitea version 1.26.3 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 3, 2026CISA-ADP
Assessed Jul 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/go-gitea/gitea/security/advisories/GHSA-2r5c-gw76-rh3w | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://blog.gitea.com/release-of-1.26.3-and-1.26.4/ | Gitea Limited | Release NotesVendor |
| https://github.com/go-gitea/gitea/pull/38059 | Gitea Limited | Issue TrackingVendor |
| https://github.com/go-gitea/gitea/pull/38173 | Gitea Limited | Issue TrackingVendor |
| https://github.com/go-gitea/gitea/releases/tag/v1.26.3 | Gitea Limited | Release NotesVendor |
| https://github.com/go-gitea/gitea/security/advisories/GHSA-2r5c-gw76-rh3w | Gitea Limited | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | Gitea Limited |
Affected Products
| Product | Versions |
|---|---|
| Gitea | <= 1.26.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 7, 2026 | CVE Modified | CISA-ADP |
| Jul 3, 2026 | New CVE Received | Gitea Limited |
Volerion