CVE-2026-70357: Gitea repository migration SSRF through DNS rebinding
Gitea validates a repository migration hostname against its network allow and block lists before invoking Git, but the Git subprocess independently resolves the hostname when connecting. An attacker who can start a migration and control the destination's DNS can change the address between validation and connection to reach a blocked internal address. The affected path is the Git clone operation; validation in the migration HTTP client's dialer does not protect the independently connecting Git subprocess.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs permission to start a repository migration and control the DNS for the migration destination hostname. They can then change that hostname's resolution after Gitea validates it but before Git connects.
What systems can the attacker reach?
The attacker can cause the Git clone subprocess to connect to an internal address that Gitea's network allow or block lists were intended to prevent. The affected connection is the Git clone operation, not the migration HTTP client's own dialer.
Do migration network allow and block lists fully mitigate this issue?
No. Those lists are checked during hostname validation, but Git independently resolves the hostname when it later connects, allowing a DNS rebinding change to bypass the earlier check.