2.1 LOW
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): Low (L)
- Vulnerable System Impact Integrity (VI): Low (L)
- Vulnerable System Impact Availability (VA): Low (L)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Exploit Maturity (E): POC (P)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
- Modified Vulnerable System Impact Integrity (MVI): Low (L)
- Modified Vulnerable System Impact Availability (MVA): Low (L)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse ignored package forgejo-cli
Forgejo Repository Migration is_migrate_allowed.go net.LookupIP server-side request forgery
A vulnerability was found in Forgejo up to 15.0.4. This issue affects the function net.LookupIP of the file services/migrations/allowlist/is_migrate_allowed.go of the component Repository Migration Handler. Performing a manipulation results in server-side request forgery. The attack can be initiated remotely. The exploit has been made public and could be used. The patch is named b313bb83f5ff22bcc0378e0e0ca7bbd58303f168. It is recommended to apply a patch to fix this issue. The project maintainer explains: "I don't intend to backport this to v15 or v16 as it is a breaking change."
References
-
VDB-397072 | Forgejo Repository Migration is_migrate_allowed.go net.LookupIP server-side request forgery technical-descriptionvdb-entry
-
-
CVE-2026-82556 | CVE Analysis and Report third-party-advisory
-
Submit #891889 | Forgejo 15.0.4 SSRF third-party-advisory
-
-
https://codeberg.org/forgejo/forgejo/pulls/13490 broken-link
Affected products
- ==15.0.2
- ==15.0.1
- ==15.0.4
- ==15.0.0
- ==15.0.3
Matching in nixpkgs
pkgs.forgejo
Self-hosted lightweight software forge
pkgs.forgejo-lts
Self-hosted lightweight software forge
pkgs.forgejo-mcp
Model Context Protocol (MCP) server for interacting with the Forgejo REST API
pkgs.forgejo-runner
Runner for Forgejo based on act
Ignored packages (1)
pkgs.forgejo-cli
CLI application for interacting with Forgejo
Package maintainers
-
@nycodeghg Marie Ramlow <tabmeier12+nix@gmail.com>
-
@bendlas Herwig Hochleitner <herwig@bendlas.net>
-
@pyrox0 Pyrox <pyrox@pyrox.dev>
-
@christoph-heiss Christoph Heiss <christoph@c8h4.io>
-
@adamcstephens Adam C. Stephens <happy.plan4249@valkor.net>
-
@tebriel tebriel <tebriel@frodux.in>
-
@emilylange Emily Lange <nix@emilylange.de>
-
@nrabulinski Nikodem Rabuliński <1337-nix@nrab.lol>