A vulnerability, which was classified as critical, was found in Gitea up to 1.26.4. Affected by this issue is some unknown functionality of the component Migration/Mirror. Such manipulation leads to server-side request forgery.

This vulnerability is referenced as CVE-2026-58508. It is possible to launch the attack remotely. No exploit is available.