CVE-2026-27779: Gitea forwarded-proto handling allows public URL spoofing
Published Jul 3, 2026
·Updated
Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting public URLs, allowing spoofed canonical URL generation.
Affected Software
1 affected component
Gitea Gitea<1.25.5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Giteato a version that resolves this vulnerability.Fixed in 1.25.5
Event History
Jul 3, 2026
CVE Published
via MITRE·08:19 PM
Data Sourced
via MITRE·08:19 PM
DescriptionWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-27779?
CVE-2026-27779 is classified with a risk score of 26.
2
How do I fix CVE-2026-27779?
To fix CVE-2026-27779, upgrade Gitea to version 1.25.5 or later.
3
What does CVE-2026-27779 affect?
CVE-2026-27779 affects Gitea versions before 1.25.5.
4
What is the impact of CVE-2026-27779?
CVE-2026-27779 allows public URL spoofing through the handling of forwarded-proto values.
5
When was CVE-2026-27779 published?
CVE-2026-27779 was published on July 3, 2026.