CVE-2026-22874
Gitea webhook and migration allow-list filtering permits SSRF
- Published
- Jul 3, 2026
- Updated
- Jul 7, 2026
- Assigning CNA
- Gitea
- Evidence observed
- Aug 17, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:NLow · next 30 days
- Percentile
- 39.3%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.
Sources
2- cve-2026-22874-gitea-ssrf-allowlistInformational
CVE-2026-22874 writeup: incomplete SSRF allow-list in Gitea webhook/migration (IPv6 transition and cloud metadata). Fixed in Gitea 1.26.3.
Proof-of-concept exploit for CVE-2026-22874, a Server-Side Request Forgery (SSRF) vulnerability in Gitea versions prior to 1.26.3. Intended for authorized security testing and mitigation validation.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.