GHSA-v8f2-2ghq-9whvHighCVSS 7.5

Gitea forwarded-proto validation allows canonical URL spoofing

Published
July 3, 2026
Last Modified
September 1, 2026

🔗 CVE IDs covered (1)

📋 Description

Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting public URLs, allowing spoofed canonical URL generation.

🎯 Affected products1

  • go/code.gitea.io/gitea:< 1.25.5

🔗 References (8)