Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-58508: Gitea Migration/Mirror DNS Rebinding Vulnerability

CVE-2026-58508 · published 1 day ago
Summary

The Gitea migration/mirror feature allows attackers to access internal systems through DNS rebinding attacks. This means an attacker could potentially access sensitive information or execute malicious code on a victim's internal network. To protect your Gitea instance, ensure that you have properly configured DNS and firewall rules to prevent unauthorized access.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
gitea gitea open source git server <= 1.26.4
Original advisory text
Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)
Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)
Severity
9.1 Critical
Exploitation
EPSS <1%
Type
CWE-284Improper Access Control
Timeline
Published13 Aug 2026
Updated14 Aug 2026
First seen13 Aug 2026
Sources
CVE-2026-58508 · MITRE
Monitor software like this
Free during beta