—
GO-2026-6083
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev
Quick fix
GO-2026-6083 — gitea.dev: upgrade to the fixed version with the command below.
go get gitea.dev@v1.27.0 Details
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/go-gitea/gitea/security/advisories/GHSA-x77v-q46j-393g [ADVISORY]
- https://github.com/go-gitea/gitea/commit/de4b8277e9cb576f2315fb03b5ab6478b42a1d31 [WEB]
- https://github.com/go-gitea/gitea/commit/f69e15afe7496cc62e96dab244629c69eb31a7bf [WEB]
- https://github.com/go-gitea/gitea/pull/38406 [WEB]
- https://github.com/go-gitea/gitea/pull/38426 [WEB]
- https://github.com/go-gitea/gitea/releases/tag/v1.27.0 [WEB]