CVE-2026-82556 | Forgejo up to 15.0.4 Repository Migration is_migrate_allowed.go net.LookupIP server-side request forgery (Issue 13433)
A vulnerability has been found in Forgejo up to 15.0.4 and classified as critical. This issue affects the function net.LookupIP of the file services/migrations/allowlist/is_migrate_allowed.go of the component Repository Migration Handler. Performing a manipulation results in server-side request forgery.
This vulnerability is identified as CVE-2026-82556. The attack can be initiated remotely. Additionally, an exploit exists.
It is recommended to apply a patch to fix this issue.
The project maintainer explains: “I don’t intend to backport this to v15 or v16 as it is a breaking change.”VulDB Recent EntriesRead More