CVE-2026-96400: Gitea migration SSRF to reserved addresses through ALLOWED_DOMAINS
With [migrations] ALLOWEDDOMAINS set to a matching entry such as or a hostname wildcard, Gitea's migration URL validation could permit reserved and link-local addresses, such as 169.254.169.254, even when ALLOWLOCALNETWORKS = false. The local-network block list did not cover these ranges, and a hostname matching the allow list was accepted regardless of its resolved address. A user who can start migrations on such an instance could reach these addresses from the Gitea server; the default empty ALLOWEDDOMAINS configuration is not affected.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs permission to start a migration on the affected Gitea instance. Exploitation also requires the instance to configure [migrations] ALLOWED_DOMAINS with a matching entry, such as * or a hostname wildcard.
Are default Gitea installations affected?
No. The default configuration, in which ALLOWED_DOMAINS is empty, is not affected.
What systems could be reached through exploitation?
The attacker can cause the Gitea server to connect to reserved or link-local addresses, including 169.254.169.254. This can occur even when ALLOW_LOCALNETWORKS is set to false if the migration hostname matches the configured allow list.
What configuration change can reduce exposure before patching?
Avoid broad ALLOWED_DOMAINS entries such as * or hostname wildcards, and remove matching entries where they are not required. Restrict migration initiation privileges to trusted users.