Blind SSRF Vulnerability in Gitea by Go-Gitea Affecting OAuth2 Avatar Synchronization
CVE-2026-23603

Currently unrated

Key Information:

Vendor

Gitea

Vendor
CVE Published:
13 August 2026

What is CVE-2026-23603?

A vulnerability exists in Gitea that allows an attacker to exploit blind server-side request forgery (SSRF) through the OAuth2 avatar synchronization feature. This is achieved via an unvalidated OpenID Connect (OIDC) picture claim, which may lead to unauthorized internal resource access. Action must be taken to mitigate this issue, especially for users relying on the affected version.

Affected Version(s)

Gitea Open Source Git Server 0 <= 1.26.4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

alimezar
cwanglab
Vext-Labs
Medoedus
ffulbtech
theluckystrike
prakhar0x01
AnuragBathani
khoadb175
.