CVE-2026-58508: Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)
Published Aug 13, 2026
·Updated
Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)
Affected Software
1 affected component
Gitea Gitea
Event History
Aug 13, 2026
CVE Published
via MITRE·04:44 PM
Data Sourced
via MITRE·04:44 PM
DescriptionWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-58508?
CVE-2026-58508 has been assigned a risk score of 65, indicating it is a moderate severity vulnerability.
2
How do I fix CVE-2026-58508?
To fix CVE-2026-58508, upgrade to Gitea version 1.27.0 or later.
3
What are the main issues associated with CVE-2026-58508?
CVE-2026-58508 involves two SSRF vulnerabilities due to DNS rebinding and missing re-validation during Gitea migrations and mirroring.
4
Does CVE-2026-58508 affect all versions of Gitea?
Yes, CVE-2026-58508 affects versions of Gitea prior to 1.27.0.
5
What is SSRF in the context of CVE-2026-58508?
SSRF, or Server-Side Request Forgery, allows an attacker to send crafted requests from the server, potentially impacting internal resources.