HIGH
coderamp-labs
CVE published 2026-08-28
CVE-2026-82289
Gitingest through 0.3.1 fails to properly validate hostnames, accepting any host with a git., gitlab., or github. prefix. This allows attackers to submit URLs with attacker-controlled hostnames, triggering outbound connections to arbitrary hosts and disclosing GitHub personal access tokens via HTTP basic credentials. The vulnerability enables attackers to bypass hostname validation, potentially leading to [truncated]