PatchSiren cyber security CVE debrief
CVE-2026-104636 Gitea CVE debrief
A Gitea vulnerability allows SSRF through Git HTTP redirects in mirrors and fetches. Gitea did not revalidate the destination after following HTTP redirects, potentially allowing a repository administrator to make Gitea's Git client send requests to a blocked address. The impact depends on the configured policy and internal services reachable from the server.
- Vendor
- Gitea
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-06
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-06
- Advisory updated
- 2026-10-07
Who should care
Gitea administrators and users, especially those with restrictive outbound host policies, should assess exposure and prioritize verification and remediation. This includes reviewing the current configuration and policies, verifying the version of Gitea being used, and assessing the potential impact on internal services. Additionally, security teams and vulnerability management teams should be aware of this vulnerability and its potential impact on Gitea
Why it matters
Defenders should prioritize verifying exposure, especially for Gitea instances with restrictive outbound host policies, and assess internal services that could be affected by SSRF.
- Potential SSRF attacks on internal services.
- Bypass of outbound host policies.
- Possible unauthorized access to internal services.
- Need for verification of exposure and remediation.
Technical summary
Gitea did not revalidate the destination after following HTTP redirects in Git HTTP operations, potentially allowing SSRF attacks through mirrors and fetches. This issue could allow a repository administrator to make Gitea's Git client send requests to a blocked address, depending on the configured policy and internal services reachable from the server. The impact of this vulnerability depends on the specific configuration and environment of the Gitea instance. For example, if the Gitea instance has restrictive outbound host policies, an attacker could potentially use this vulnerability to bypass those policies and access internal services. Additionally, if the instance is configured to allow repository mirrorm
Defensive priority
Defenders should prioritize verifying exposure, especially for Gitea instances with restrictive outbound host policies, and assess internal services that could be affected by SSRF.
Recommended defensive actions
- Verify Gitea instance exposure, especially for versions 0 to 1.27.3, and assess internal services that could be affected by SSRF.
- Review and update outbound host policies to prevent potential SSRF attacks.
- Monitor Gitea instance logs for suspicious activity.
- Consider upgrading to Gitea version 28.0.0 or later.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and source item provide details on the vulnerability. However, the corpus does not establish specific versions, exploitation, impact, or remediation, requiring verification from official sources.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-104636 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-104636
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-104636 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104636
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Gitea SSRF through Git HTTP redirects in mirrors and fetches
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/104xxx/CVE-2026-104636.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/go-gitea/gitea/security/advisories/GHSA-g4hw-fg4c-89mq
Supplemental source - vendor-advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/go-gitea/gitea/pull/39426
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://blog.gitea.com/release-of-28.0.0/
Supplemental source - release-notes
-
Source reference
Unverified legacy reference
URL: https://github.com/go-gitea/gitea/releases/tag/v28.0.0
Supplemental source - release-notes
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.