blob: 5e0afba26812d9d65d1f7f4827cdbcebefe76768 [file]
id: GO-2026-6083
modules:
- module: gitea.dev
versions:
- fixed: 1.27.0
vulnerable_at: 1.27.0-rc0
summary: |-
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture
claim in gitea.dev
cves:
- CVE-2026-23603
ghsas:
- GHSA-x77v-q46j-393g
references:
- advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-x77v-q46j-393g
- web: https://github.com/go-gitea/gitea/commit/de4b8277e9cb576f2315fb03b5ab6478b42a1d31
- web: https://github.com/go-gitea/gitea/commit/f69e15afe7496cc62e96dab244629c69eb31a7bf
- web: https://github.com/go-gitea/gitea/pull/38406
- web: https://github.com/go-gitea/gitea/pull/38426
- web: https://github.com/go-gitea/gitea/releases/tag/v1.27.0
source:
id: GHSA-x77v-q46j-393g
created: 2026-07-23T18:55:30.528708-04:00
review_status: UNREVIEWED