CVE-2026-82556: Forgejo Repository Migration is_migrate_allowed.go net.LookupIP server-side request forgery

Published Aug 30, 2026
·
Updated

A vulnerability was found in Forgejo up to 15.0.4. This issue affects the function net.LookupIP of the file services/migrations/allowlist/ismigrateallowed.go of the component Repository Migration Handler. Performing a manipulation results in server-side request forgery. The attack can be initiated remotely. The exploit has been made public and could be used. The patch is named b313bb83f5ff22bcc0378e0e0ca7bbd58303f168. It is recommended to apply a patch to fix this issue. The project maintainer explains: "I don't intend to backport this to v15 or v16 as it is a breaking change."

Affected Software

1 affected component
Forgejo<=15.0.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Forgejo Repository Migration Handler to a version that resolves this vulnerability.

    Patch b313bb83f5ff22bcc0378e0e0ca7bbd58303f168

Event History

Aug 30, 2026
CVE Published
via MITRE·05:45 PM
Data Sourced
via MITRE·05:45 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

The attack can be initiated remotely and requires low privileges. It affects the Repository Migration Handler, so exposure is tied to deployments where repository migration functionality is available to such users.

2

Which Forgejo versions should be considered affected?

Forgejo versions up to and including 15.0.4 are reported as affected. The available information does not state whether later versions are affected or fixed.

3

What should teams do if they are running an affected release?

Apply the patch identified as b313bb83f5ff22bcc0378e0e0ca7bbd58303f168. The maintainer states that this change will not be backported to v15 or v16 because it is a breaking change.

4

How can I determine whether my deployment is exposed?

Confirm the Forgejo version and whether the Repository Migration Handler is enabled or available to low-privileged users. Deployments running 15.0.4 or earlier should be treated as affected based on the reported version range.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203