| id: GO-2026-6083 |
| modules: |
| - module: gitea.dev |
| versions: |
| - fixed: 1.27.0 |
| vulnerable_at: 1.27.0-rc0 |
| summary: |- |
| Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture |
| claim in gitea.dev |
| cves: |
| - CVE-2026-23603 |
| ghsas: |
| - GHSA-x77v-q46j-393g |
| references: |
| - advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-x77v-q46j-393g |
| - web: https://github.com/go-gitea/gitea/commit/de4b8277e9cb576f2315fb03b5ab6478b42a1d31 |
| - web: https://github.com/go-gitea/gitea/commit/f69e15afe7496cc62e96dab244629c69eb31a7bf |
| - web: https://github.com/go-gitea/gitea/pull/38406 |
| - web: https://github.com/go-gitea/gitea/pull/38426 |
| - web: https://github.com/go-gitea/gitea/releases/tag/v1.27.0 |
| source: |
| id: GHSA-x77v-q46j-393g |
| created: 2026-07-23T18:55:30.528708-04:00 |
| review_status: UNREVIEWED |