Server-side Request Forgery (SSRF) Affecting github.com/go-gitea/gitea/services/repository package, versions <1.27.0


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.27% (19th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMGOGITEAGITEASERVICESREPOSITORY-18752781
  • published13 Aug 2026
  • disclosed21 Jul 2026
  • creditcyberlanc3r

Introduced: 21 Jul 2026

CVE-2026-57894  (opens in a new tab)
CWE-918  (opens in a new tab)

How to fix?

Upgrade github.com/go-gitea/gitea/services/repository to version 1.27.0 or higher.

Overview

Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) in the repository migration and mirror synchronization process. An attacker can access internal Git repositories and exfiltrate sensitive data by submitting a crafted migration URL that causes the server to follow an HTTP redirect to an otherwise restricted internal endpoint.

Note: This is only exploitable if repository migrations are enabled and the attacker has a low-privileged account or self-registration is permitted, and the server can reach internal Git HTTP(S) services that are not directly accessible to the attacker.

Workaround

This vulnerability can be mitigated by disabling Git HTTP redirects for migration clone and mirror fetch operations, or by enforcing strict egress controls to prevent the server from accessing internal resources.

CVSS Base Scores

version 4.0
version 3.1