Skip to main content
Vulnerability Database/CVE-2026-82556

CVE-2026-82556: Forgejo Repository Migration SSRF Vulnerability

CVE-2026-82556 is an SSRF vulnerability in Forgejo's Repository Migration Handler affecting versions up to 15.0.4. Attackers can manipulate the net.LookupIP function to perform unauthorized requests. This article covers technical details, affected versions, impact assessment, and mitigation strategies.

Published:

CVE-2026-82556 Overview

CVE-2026-82556 is a server-side request forgery (SSRF) vulnerability in Forgejo versions up to 15.0.4. The flaw resides in the net.LookupIP function within services/migrations/allowlist/is_migrate_allowed.go, part of the Repository Migration Handler. An authenticated attacker can manipulate migration requests to coerce the Forgejo server into issuing HTTP requests to unintended internal or external destinations. The exploit details have been publicly disclosed, increasing the risk of opportunistic abuse. The maintainers released patch commit b313bb83f5ff22bcc0378e0e0ca7bbd58303f168 but explicitly declined to backport the fix to v15 or v16 because it introduces a breaking change.

Critical Impact

Authenticated users can abuse the repository migration feature to send server-originated requests to internal services, potentially exposing metadata endpoints, internal APIs, or restricted network resources.

Affected Products

  • Forgejo up to and including version 15.0.4
  • Forgejo v15 branch (no backport planned)
  • Forgejo v16 branch (no backport planned)

Discovery Timeline

  • 2026-08-30 - CVE-2026-82556 published to NVD
  • 2026-08-31 - Last updated in NVD database

Technical Details for CVE-2026-82556

Vulnerability Analysis

Forgejo's Repository Migration Handler validates whether a target URL is permitted before initiating a migration. The allowlist logic in is_migrate_allowed.go relies on net.LookupIP to resolve the hostname and compare returned addresses against blocked ranges. This DNS-based validation is susceptible to time-of-check to time-of-use inconsistencies and DNS rebinding, since the resolution performed during validation may differ from the resolution performed when the migration client actually connects.

The weakness is classified as [CWE-918] Server-Side Request Forgery. An attacker with a valid Forgejo account can supply a repository URL that passes the allowlist check yet resolves to an internal address at fetch time. The Forgejo server then issues an outbound request on behalf of the attacker.

Root Cause

The root cause is reliance on a single DNS lookup for allowlist enforcement without pinning the resolved address for the subsequent HTTP request. Because DNS answers can change between validation and use, or return multiple records including private ranges, the allowlist can be bypassed. The maintainers' fix restructures this validation flow, which is why it is treated as a breaking change and not backported.

Attack Vector

The attack is initiated remotely over the network by a user with low-privilege authenticated access to the Forgejo instance. The attacker triggers a repository migration pointing at a domain they control. The domain is configured to return an allowlisted IP during validation and an internal IP such as 127.0.0.1, 169.254.169.254, or an RFC1918 address during the migration fetch. This causes Forgejo to issue HTTP requests to internal endpoints, returning response data or side effects to the attacker via migration logs and error messages.

No verified proof-of-concept code is published in the referenced advisories. Refer to the Forgejo Issue Tracker Entry and Forgejo Pull Request Review for maintainer discussion of the flaw and remediation.

Detection Methods for CVE-2026-82556

Indicators of Compromise

  • Repository migration requests targeting hostnames that resolve to private IP ranges such as 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, or 169.254.169.254.
  • Outbound HTTP requests from the Forgejo application server to internal services that do not normally receive traffic from it.
  • Repeated migration attempts from a single account against domains with short DNS time-to-live values, indicative of rebinding attempts.

Detection Strategies

  • Correlate Forgejo migration audit logs with DNS resolver logs to identify hostnames that resolved to different addresses within a short interval.
  • Alert on any egress from the Forgejo host to cloud metadata endpoints, loopback interfaces, or link-local addresses.
  • Baseline the set of destinations reached by the Forgejo service account and flag deviations tied to migration operations.

Monitoring Recommendations

  • Enable verbose logging on the Repository Migration Handler and forward events to a centralized SIEM or data lake.
  • Monitor authentication events for newly created low-privilege accounts that immediately initiate migrations.
  • Track egress traffic from Forgejo through a filtering proxy that logs full request URLs and response codes.

How to Mitigate CVE-2026-82556

Immediate Actions Required

  • Restrict who can initiate repository migrations by tightening user permissions and disabling migration for untrusted accounts.
  • Place the Forgejo server behind an egress proxy that blocks requests to RFC1918, loopback, and cloud metadata address ranges.
  • Review recent migration activity for suspicious target hostnames or destinations resolving to internal addresses.

Patch Information

The fix is committed as b313bb83f5ff22bcc0378e0e0ca7bbd58303f168. Because the maintainers classify the change as breaking, it will not be backported to v15 or v16. Operators should plan an upgrade to a Forgejo release that includes the patched allowlist logic. See the Forgejo Commit Update for the full change set.

Workarounds

  • Enforce network-level egress filtering so the Forgejo host cannot reach internal management interfaces, cloud metadata services, or loopback ports.
  • Disable the repository migration feature or limit it to administrator accounts until the environment is upgraded.
  • Deploy a DNS resolver that rejects responses containing private, loopback, or link-local addresses for external names.
bash
# Configuration example: block egress to sensitive internal ranges via iptables
iptables -A OUTPUT -m owner --uid-owner forgejo -d 127.0.0.0/8 -j REJECT
iptables -A OUTPUT -m owner --uid-owner forgejo -d 10.0.0.0/8 -j REJECT
iptables -A OUTPUT -m owner --uid-owner forgejo -d 172.16.0.0/12 -j REJECT
iptables -A OUTPUT -m owner --uid-owner forgejo -d 192.168.0.0/16 -j REJECT
iptables -A OUTPUT -m owner --uid-owner forgejo -d 169.254.0.0/16 -j REJECT

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.