Blind SSRF Vulnerability in Gitea by Go-Gitea Affecting OAuth2 Avatar Synchronization
CVE-2026-23603
Currently unrated
What is CVE-2026-23603?
A vulnerability exists in Gitea that allows an attacker to exploit blind server-side request forgery (SSRF) through the OAuth2 avatar synchronization feature. This is achieved via an unvalidated OpenID Connect (OIDC) picture claim, which may lead to unauthorized internal resource access. Action must be taken to mitigate this issue, especially for users relying on the affected version.
Affected Version(s)
Gitea Open Source Git Server 0 <= 1.26.4
