CVE-2018-15192: Gitea

High severity, CVSS 8.6. EPSS: 2.1% chance of exploitation in the next 30 days.

An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access intranet services.

Affected products

  • Gitea Gitea: before 1.5.0 (fixed in 1.5.0); version 1.5.0 only
  • Gogs Gogs: up to and including 0.11.53

Published 2018-08-08. Last modified 2026-06-17.