AI analysis
Gitea's repository migration and pull-mirror egress checks can be bypassed when a hostname returns multiple DNS answers, because the address that was validated is not necessarily the address Git later connects to. A low-privileged user who is allowed to create migrations or mirrors can use that gap to point the server at internal services, reading from and writing to reachable internal Git or HTTP endpoints. Content from those internal responses can also be disclosed through migration and mirror error messages. Self-hosted Gitea deployments that grant such users migration or mirror rights are affected; the advisory data does not name the vulnerable version range. There is no known public proof of concept, and the issue is not listed in CISA KEV.
What to do: Upgrade Gitea to the vendor release that fixes this migration and pull-mirror egress issue, and do not rely on unpatched builds. Until then, limit who can create repository migrations and pull mirrors to trusted administrators, and block the Gitea host from reaching internal Git and HTTP services. Review migration and mirror error logs for unexpected internal response content.
Estimated exposure
largeTens of thousands of internet-exposed Gitea instances (unpatched share unknown) — Order-of-magnitude estimate from Gitea's widespread use as a self-hosted Git forge and typical public internet-scan footprints for exposed instances; the advisory gives no affected-version or install counts, so the unpatched share is…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Gitea's repository migration and pull mirror egress checks could be bypassed with a hostname that returns multiple DNS answers, because the address that was validated was not necessarily the address Git later connected to. A low-privileged user who can create migrations or mirrors could direct the server to internal services, reading from and writing to reachable internal Git or HTTP endpoints. Content from internal responses could additionally be disclosed through migration and mirror error messages.