CVE-2026-70357: Gitea repository migration SSRF through DNS rebinding

Published Oct 6, 2026
·
Updated

Gitea validates a repository migration hostname against its network allow and block lists before invoking Git, but the Git subprocess independently resolves the hostname when connecting. An attacker who can start a migration and control the destination's DNS can change the address between validation and connection to reach a blocked internal address. The affected path is the Git clone operation; validation in the migration HTTP client's dialer does not protect the independently connecting Git subprocess.

Affected Software

1 affected component
Gitea Gitea

Event History

Oct 6, 2026
CVE Published
via MITRE·07:24 PM
Data Sourced
via MITRE·07:24 PM
DescriptionWeakness
Data Sourced
via NVD·08:17 PM
DescriptionWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs permission to start a repository migration and control the DNS for the migration destination hostname. They can then change that hostname's resolution after Gitea validates it but before Git connects.

2

What systems can the attacker reach?

The attacker can cause the Git clone subprocess to connect to an internal address that Gitea's network allow or block lists were intended to prevent. The affected connection is the Git clone operation, not the migration HTTP client's own dialer.

3

Do migration network allow and block lists fully mitigate this issue?

No. Those lists are checked during hostname validation, but Git independently resolves the hostname when it later connects, allowing a DNS rebinding change to bypass the earlier check.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203