Medium [CVE-2026-82556] Server-side request forgery via repository migration
This medium-severity Red Hat Linux advisory covers CVE-2026-82556 affecting Assisted Installer for Red Hat OpenShift Container Platform 2, AWS Load Balancer Operator, Builds for Red Hat OpenShift.
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
A vulnerability was found in Forgejo up to 15.0.4. This issue affects the function net.
LookupIP of the file services/migrations/allowlist/is_migrate_allowed.go of the component Repository Migration Handler. Performing a manipulation results in server-side request forgery.
The attack can be initiated remotely. The exploit has been made public and could be used.
The patch is named b313bb83f5ff22bcc0378e0e0ca7bbd58303f168. It is recommended to apply a patch to fix this issue.
The project maintainer explains: "I don't intend to backport this to v15 or v16 as it is a breaking change." A remote attacker could exploit a server-side request forgery (SSRF) vulnerability by manipulating the `net. LookupIP` function within the Repository Migration Handler.
This could allow the attacker to force the server to make requests to arbitrary network resources, potentially leading to information disclosure or access to internal services. Red Hat severity: Moderate — CVSS 6.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
Weakness: CWE-918.
Affected products named by the advisory: Assisted Installer for Red Hat OpenShift Container Platform 2; AWS Load Balancer Operator; Builds for Red Hat OpenShift; cert-manager Operator for Red Hat OpenShift; and 53 more.
- 15.0.4
Official advisory · high-confidence parse· fetched 57 minutes ago·verify at source
Fixed versions
No fixed release is recorded yet. That does not prove no patch exists — confirm against the vendor advisory.
Official advisory · high-confidence parse· fetched 57 minutes ago·verify at source
Mitigation
The source record does not include mitigation steps. That is not a statement that no fix exists — read the vendor advisory below for the authoritative guidance.
Official advisory · high-confidence parse· fetched 57 minutes ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.