Review reviewCritical
CVE-2026-22874
Gitea Gitea Open Source Git Server
Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.
- CVSS
- 9.6
- EPSS
- 0.55% 43.1% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.04