Junglewise Threat Intelligence

CVE-2026-23603: Gitea SSRF in OAuth2 avatar synchronization

CVE-2026-23603 · Severity: low · CVSS 3.1 · Published 2026-07-21

Technologies: code.gitea.io/gitea (Go), Gitea, gitea.dev (Go). Vendors: Go, Gitea.

Executive brief

Gitea, a popular self-hosted Git service, is vulnerable to a security flaw when configured to automatically update user profile pictures from external login providers like Google or Okta. An attacker can provide a malicious link that forces the Gitea server to scan or interact with internal company systems that are normally hidden from the public internet. This could allow an attacker to probe internal network services or access sensitive cloud configuration data.

Technical details

A blind Server-Side Request Forgery (SSRF) exists in Gitea's OAuth2/OIDC avatar synchronization logic. When `[oauth2_client] UPDATE_AVATAR = true` is enabled, the `oauth2UpdateAvatarIfNeed` function in `routers/web/auth/oauth.go` uses Go's default `http.Get(url)` to fetch user avatars without host or IP restrictions. A low-privileged user who can control their OIDC `picture` claim can trigger GET requests to internal resources, including loopback (127.0.0.1), RFC 1918 private addresses, and cloud metadata endpoints (169.254.169.254). While the vulnerability is primarily blind, if an internal service returns a valid image, the data may be stored as the user's avatar, providing a limited data retrieval primitive. The issue is resolved in version 1.27.0 by implementing proper host matching and restricted transport.

Affected products

  • Gitea Gitea < 1.27.0

Timeline

  • 2026-07-13: disclosed: Initial disclosure to Gitea maintainers
  • 2026-07-21: advisory: GitHub Advisory published
  • 2026-07-21: patched: Fix released in version 1.27.0

References

Related threats