CVE-2026-101029

Source
https://cve.org/CVERecord?id=CVE-2026-101029
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-101029.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-101029
Aliases
  • GHSA-6g2h-xpg3-rm48
Published
2026-10-06T19:23:26Z
Modified
2026-10-07T10:46:49Z
Summary
Gitea migration and pull mirror SSRF through multi-answer DNS
Details

Gitea's repository migration and pull mirror egress checks could be bypassed with a hostname that returns multiple DNS answers, because the address that was validated was not necessarily the address Git later connected to. A low-privileged user who can create migrations or mirrors could direct the server to internal services, reading from and writing to reachable internal Git or HTTP endpoints. Content from internal responses could additionally be disclosed through migration and mirror error messages.

Database specific
{
    "cna_assigner": "Gitea",
    "cwe_ids": [
        "CWE-209",
        "CWE-367",
        "CWE-918"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/101xxx/CVE-2026-101029.json"
}
References

Affected packages

Git / github.com/go-gitea/gitea

Affected ranges

Type
GIT
Repo
https://github.com/go-gitea/gitea
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last Affected
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.27.3"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v0.*
v0.9.99
v1.*
v1.0.0
v1.1.0
v1.10.0-dev
v1.10.0-rc1
v1.10.5
v1.11.0-dev
v1.11.0-rc1
v1.12.0-dev
v1.13.0-dev
v1.14.0-dev
v1.15.0-dev
v1.15.0-rc1
v1.16.0-dev
v1.16.0-rc1
v1.17.0-dev
v1.18.0-dev
v1.18.0-rc0
v1.19.0-dev
v1.19.0-rc0
v1.20.0-dev
v1.20.0-rc0
v1.21.0-dev
v1.21.0-rc0
v1.22.0-dev
v1.22.0-rc0
v1.22.0-rc1
v1.23.0-dev
v1.24.0-dev
v1.25.0-dev
v1.26.0-dev
v1.27.0
v1.27.0-dev
v1.27.0-rc0
v1.27.1
v1.27.2
v1.27.3
v1.28.0-dev
v1.5.0-dev
v1.5.0-rc1
v1.6.0-dev
v1.6.0-rc1
v1.7.0-dev
v1.9.0-dev
v1.9.0-rc1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-101029.json"