« Volver al listado

CVE-2026-101027

Estado: RecibidaSin puntuar—

When `[migrations] ALLOWED_DOMAINS` was configured, a hostname matching the allow list was accepted without checking its resolved address against the local-network restrictions. A user who can start repository migrations and control the DNS of an allowed hostname could make it resolve to loopback or private addresses and bypass `ALLOW_LOCALNETWORKS = false`, reaching internal services from the Gitea server. Instances without `ALLOWED_DOMAINS` configured are not affected by this specific bypass.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

FIRST aún no ha puntuado esta CVE (habitual en CVEs muy recientes o rechazadas).

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-101027",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "88ee5874-cf24-4952-aea0-31affedb7ff2",
      "affectedData": [
        {
          "vendor": "Gitea",
          "product": "Gitea",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "semver",
              "lessThanOrEqual": "1.27.3"
            }
          ],
          "packageName": "gitea.dev",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-10-06T20:17:08.233",
  "references": [
    {
      "url": "https://blog.gitea.com/release-of-28.0.0/",
      "source": "88ee5874-cf24-4952-aea0-31affedb7ff2"
    },
    {
      "url": "https://github.com/go-gitea/gitea/pull/39426",
      "source": "88ee5874-cf24-4952-aea0-31affedb7ff2"
    },
    {
      "url": "https://github.com/go-gitea/gitea/releases/tag/v28.0.0",
      "source": "88ee5874-cf24-4952-aea0-31affedb7ff2"
    },
    {
      "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-fqjr-23c8-gg9m",
      "source": "88ee5874-cf24-4952-aea0-31affedb7ff2"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "When `[migrations] ALLOWED_DOMAINS` was configured, a hostname matching the allow list was accepted without checking its resolved address against the local-network restrictions. A user who can start repository migrations and control the DNS of an allowed hostname could make it resolve to loopback or private addresses and bypass `ALLOW_LOCALNETWORKS = false`, reaching internal services from the Gitea server. Instances without `ALLOWED_DOMAINS` configured are not affected by this specific bypass."
    }
  ],
  "lastModified": "2026-10-06T20:17:08.233",
  "sourceIdentifier": "88ee5874-cf24-4952-aea0-31affedb7ff2"
}