CVE Vulnerabilities

CVE-2026-101027

Published: Oct 06, 2026 | Modified: Oct 06, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

When [migrations] ALLOWED_DOMAINS was configured, a hostname matching the allow list was accepted without checking its resolved address against the local-network restrictions. A user who can start repository migrations and control the DNS of an allowed hostname could make it resolve to loopback or private addresses and bypass ALLOW_LOCALNETWORKS = false, reaching internal services from the Gitea server. Instances without ALLOWED_DOMAINS configured are not affected by this specific bypass.

References