Bug 2526028 (CVE-2026-82556)

Summary: CVE-2026-82556 net: golang: codeberg.org/forgejo/forgejo: Forgejo: Server-side request forgery via repository migration
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerability-draftAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aazores, abarbaro, akhatavk, akostadi, akoudelk, alebedev, alizardo, amasferr, amctagga, anjoseph, anpicker, ansmith, anthomas, aoconnor, aos-team-art-private, aruklets, asatyam, asdas, ataylor, bbrownin, bniver, bparees, chfoley, ckandaga, cmah, crizzo, dakwon, dhanak, diagrawa, dkeler, dmayorov, doconnor, dpaolell, drosa, dschmidt, dsimansk, dymurray, eaguilar, ebaron, eborisov, eglynn, ehelms, ehugonne, flucifre, gbenhaim, ggainey, gmeno, gparvin, groman, hasun, ibolton, jbritton, jburrell, jcantril, jchui, jdelft, jeder, jfula, jhe, jjoyce, jlanda, jlledo, jmatsuok, jmatthew, jmontleo, jowilson, jpasqual, jprabhak, jpretori, jschluet, jtolenti, jupierce, juwatts, kingland, kshier, ktsao, lball, lbragsta, lchilton, lgamliel, lgarciaa, lhh, mbenjamin, mbiarnes, mburns, mdellweg, mgarciac, mhackett, mhulan, mnovotny, mrunge, mwringe, nboldt, ngough, niyer, nmoumoul, nyancey, oaljalju, ometelka, osousa, pantinor, pcreech, pgaikwad, pjindal, ppalepu, ppostler, prdhamdh, psrna, ptisnovs, pvasanth, rchan, rekumar, rgodfrey, rhaigner, rhel-process-autobot, rjohnson, rojacob, sabiswas, sakbas, sausingh, sbratsla, sdawley, sfeifer, sghai, sidsharm, simaishi, slucidi, smallamp, sostapov, sseago, stcannon, suppawar, swoodman, syedriko, teagle, thason, tmalecek, tsedmik, twaugh, tzivkovi, vereddy, veshanka, vimartin, vkarehfa, vlaad, vvoronko, watson-tool-maintainers, wenshen, whayutin, wtam, xdharmai, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Forgejo. A remote attacker could exploit a server-side request forgery (SSRF) vulnerability by manipulating the `net.LookupIP` function within the Repository Migration Handler. This could allow the attacker to force the server to make requests to arbitrary network resources, potentially leading to information disclosure or access to internal services.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-08-30 17:51:13 UTC
A vulnerability was found in Forgejo up to 15.0.4. This issue affects the function net.LookupIP of the file services/migrations/allowlist/is_migrate_allowed.go of the component Repository Migration Handler. Performing a manipulation results in server-side request forgery. The attack can be initiated remotely. The exploit has been made public and could be used. The patch is named b313bb83f5ff22bcc0378e0e0ca7bbd58303f168. It is recommended to apply a patch to fix this issue. The project maintainer explains: "I don't intend to backport this to v15 or v16 as it is a breaking change."