CVE-2026-22874: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter

Severity: Critical

CVSS Score: 9.6

Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.