A vulnerability was found in Gitea up to 1.26.4. It has been classified as problematic. This issue affects some unknown processing of the component Migration Asset Downloads. The manipulation leads to server-side request forgery.
This vulnerability is listed as CVE-2026-59765. The attack may be initiated remotely. There is no available exploit.