PatchSiren

Forgejo CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW Forgejo CVE published 2026-08-30

CVE-2026-82556

The CVE-2026-82556 vulnerability affects Forgejo up to version 15.0.4, specifically in the Repository Migration Handler component. The issue arises from the manipulation of the net.LookupIP function in the services/migrations/allowlist/is_migrate_allowed.go file, leading to a server-side request forgery vulnerability. The attack can be initiated remotely, and the exploit has been made public. To address t [truncated]