CVE-2026-27779

CVE-2026-27779CVE-2026-27779

Description

Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting public URLs, allowing spoofed canonical URL generation.

Scoring

Last modified2026-07-03
Sourced from NVD. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.