CVE-2026-22874
CRITICAL
NVD
CVSS Score
9.6
Severity
CRITICAL
Published
Jul 03, 2026
Vendor
unknown
Description
Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.
Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.