Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim (CVE-2026-23603)
Gitea versions prior to 1.27.0 have a blind Server-Side Request Forgery (SSRF) vulnerability in the OAuth2 avatar synchronization feature when the setting UPDATE_AVATAR is enabled. The vulnerability arises because Gitea fetches the avatar URL from the OAuth2/OIDC provider's picture claim using an unvalidated HTTP GET request without restricting outbound hosts or IPs. A low-privileged user who can control their picture claim can cause the Gitea server to make arbitrary HTTP requests to internal or private network addresses. This can lead to internal network probing or interaction with localhost-only services. The vulnerability is blind because non-image responses are discarded, but if an internal service returns a valid image, it may be stored as the user's avatar, allowing limited data retrieval.
AI Analysis
Technical Summary
When the [oauth2_client] UPDATE_AVATAR setting is enabled in Gitea, the server fetches the avatar URL provided by the OAuth2/OIDC provider's picture claim using Go's default HTTP client without applying any host or IP restrictions. This allows a low-privileged OAuth2/OIDC user who can influence their picture claim to cause the Gitea server to perform arbitrary outbound HTTP GET requests, including to loopback, private network, and link-local IP addresses. The vulnerable code path does not enforce the host restrictions that other outbound fetches in Gitea do. The SSRF is blind because the response content is not directly returned to the attacker, but impact can increase if internal services return valid image data within size limits, which may be stored as the user's avatar. This can enable internal service probing and limited response retrieval depending on network access controls and deployment environment.
Potential Impact
A low-privileged OAuth2/OIDC user with control over their picture claim can cause the Gitea server to make arbitrary outbound HTTP GET requests to internal or private network addresses. This can lead to internal network reconnaissance and interaction with services not accessible from the public internet, such as cloud metadata services, localhost-only services, or internal admin panels. The SSRF is blind by default, limiting direct data exfiltration, but if internal endpoints return valid image data within the configured avatar size limit, the attacker may retrieve limited information by having that data stored as their avatar.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, consider disabling the [oauth2_client] UPDATE_AVATAR setting to prevent server-side fetching of user-controlled avatar URLs. Review and restrict OAuth2/OIDC provider configurations to limit attacker control over the picture claim. Monitor for updates from the Gitea project regarding an official fix and apply it promptly once released.
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim (CVE-2026-23603)
Description
Gitea versions prior to 1.27.0 have a blind Server-Side Request Forgery (SSRF) vulnerability in the OAuth2 avatar synchronization feature when the setting UPDATE_AVATAR is enabled. The vulnerability arises because Gitea fetches the avatar URL from the OAuth2/OIDC provider's picture claim using an unvalidated HTTP GET request without restricting outbound hosts or IPs. A low-privileged user who can control their picture claim can cause the Gitea server to make arbitrary HTTP requests to internal or private network addresses. This can lead to internal network probing or interaction with localhost-only services. The vulnerability is blind because non-image responses are discarded, but if an internal service returns a valid image, it may be stored as the user's avatar, allowing limited data retrieval.
CVSS v3.1
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
When the [oauth2_client] UPDATE_AVATAR setting is enabled in Gitea, the server fetches the avatar URL provided by the OAuth2/OIDC provider's picture claim using Go's default HTTP client without applying any host or IP restrictions. This allows a low-privileged OAuth2/OIDC user who can influence their picture claim to cause the Gitea server to perform arbitrary outbound HTTP GET requests, including to loopback, private network, and link-local IP addresses. The vulnerable code path does not enforce the host restrictions that other outbound fetches in Gitea do. The SSRF is blind because the response content is not directly returned to the attacker, but impact can increase if internal services return valid image data within size limits, which may be stored as the user's avatar. This can enable internal service probing and limited response retrieval depending on network access controls and deployment environment.
Potential Impact
A low-privileged OAuth2/OIDC user with control over their picture claim can cause the Gitea server to make arbitrary outbound HTTP GET requests to internal or private network addresses. This can lead to internal network reconnaissance and interaction with services not accessible from the public internet, such as cloud metadata services, localhost-only services, or internal admin panels. The SSRF is blind by default, limiting direct data exfiltration, but if internal endpoints return valid image data within the configured avatar size limit, the attacker may retrieve limited information by having that data stored as their avatar.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, consider disabling the [oauth2_client] UPDATE_AVATAR setting to prevent server-side fetching of user-controlled avatar URLs. Review and restrict OAuth2/OIDC provider configurations to limit attacker control over the picture claim. Monitor for updates from the Gitea project regarding an official fix and apply it promptly once released.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-x77v-q46j-393g
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-23603"]
- Ecosystems
- ["Go"]
- Database Specific Severity
- LOW
- Cvss Version
- 3.1
Threat ID: 6a600abb9c2644c7f8fe2b94
Added to database: 07/22/2026, 00:11:39 UTC
Last enriched: 07/22/2026, 00:52:19 UTC
Last updated: 07/22/2026, 01:35:53 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.