AI analysis
CVE-2026-70357 is a server-side request forgery (CWE-918) in Gitea repository migration caused by a time-of-check/time-of-use gap on DNS. Gitea checks the migration hostname against its network allow and block lists, then starts Git; the Git subprocess resolves that hostname again when it connects, so an attacker who can start a migration and control the destination DNS can change the address after validation and point the clone at a blocked internal address. The migration HTTP client's dialer checks do not cover this Git clone path. CVSS 3.1 rates it 7.5 (high) with network access, low complexity, no privileges or user interaction, and high integrity impact only (no confidentiality or availability impact in the score). No affected version range is stated in the advisory data; there is no known public proof of concept and it is not listed in CISA KEV.
What to do: Treat repository migration as untrusted until a vendor patch is confirmed: limit who can start migrations, and block the Gitea host from reaching internal or sensitive networks so a bypassed allow/block list cannot be used as a pivot. Re-check migration allow and block lists, but do not rely on hostname checks alone, because Git resolves the name separately from the migration HTTP client. Consult the Gitea advisory for the fixed release—no patched version range is given in this data—and upgrade as soon as it is published.
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Gitea validates a repository migration hostname against its network allow and block lists before invoking Git, but the Git subprocess independently resolves the hostname when connecting. An attacker who can start a migration and control the destination's DNS can change the address between validation and connection to reach a blocked internal address. The affected path is the Git clone operation; validation in the migration HTTP client's dialer does not protect the independently connecting Git subprocess.