Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-82556

Опубликовано: 30 авг. 2026
Источник: redhat
CVSS3: 6.3
EPSS Низкий

Описание

A vulnerability was found in Forgejo up to 15.0.4. This issue affects the function net.LookupIP of the file services/migrations/allowlist/is_migrate_allowed.go of the component Repository Migration Handler. Performing a manipulation results in server-side request forgery. The attack can be initiated remotely. The exploit has been made public and could be used. The patch is named b313bb83f5ff22bcc0378e0e0ca7bbd58303f168. It is recommended to apply a patch to fix this issue. The project maintainer explains: "I don't intend to backport this to v15 or v16 as it is a breaking change."

A flaw was found in Forgejo. A remote attacker could exploit a server-side request forgery (SSRF) vulnerability by manipulating the net.LookupIP function within the Repository Migration Handler. This could allow the attacker to force the server to make requests to arbitrary network resources, potentially leading to information disclosure or access to internal services.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Hardened Imagesgolang1.25Not affected
Red Hat Hardened Imagesgolang1.26Not affected
Red Hat Hardened Imagesgolang1.27Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=2526028net: golang: codeberg.org/forgejo/forgejo: Forgejo: Server-side request forgery via repository migration

EPSS

Процентиль: 12%
0.00214
Низкий

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.3
nvd
17 дней назад

A vulnerability was found in Forgejo up to 15.0.4. This issue affects the function net.LookupIP of the file services/migrations/allowlist/is_migrate_allowed.go of the component Repository Migration Handler. Performing a manipulation results in server-side request forgery. The attack can be initiated remotely. The exploit has been made public and could be used. The patch is named b313bb83f5ff22bcc0378e0e0ca7bbd58303f168. It is recommended to apply a patch to fix this issue. The project maintainer explains: "I don't intend to backport this to v15 or v16 as it is a breaking change."

CVSS3: 6.3
debian
17 дней назад

A vulnerability was found in Forgejo up to 15.0.4. This issue affects ...

CVSS3: 6.3
github
17 дней назад

A vulnerability was found in Forgejo up to 15.0.4. This issue affects the function net.LookupIP of the file services/migrations/allowlist/is_migrate_allowed.go of the component Repository Migration Handler. Performing a manipulation results in server-side request forgery. The attack can be initiated remotely. The exploit has been made public and could be used. The patch is named b313bb83f5ff22bcc0378e0e0ca7bbd58303f168. It is recommended to apply a patch to fix this issue. The project maintainer explains: "I don't intend to backport this to v15 or v16 as it is a breaking change."

EPSS

Процентиль: 12%
0.00214
Низкий

6.3 Medium

CVSS3