Server-side Request Forgery (SSRF) Affecting gitea.dev/routers/web/auth package, versions <1.27.0


Severity

Recommended
0.0
low
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.25% (16th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITEADEVROUTERSWEBAUTH-18601958
  • published10 Aug 2026
  • disclosed21 Jul 2026
  • creditUnknown

Introduced: 21 Jul 2026

CVE-2026-23603  (opens in a new tab)
CWE-918  (opens in a new tab)

How to fix?

Upgrade gitea.dev/routers/web/auth to version 1.27.0 or higher.

Overview

Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the oauth2UpdateAvatarIfNeed function. An attacker can cause the server to make arbitrary outbound HTTP GET requests by supplying a crafted avatar URL through the OAuth2/OIDC picture claim. This can result in unauthorized access to internal network resources, including loopback, private, or link-local addresses, potentially exposing sensitive information or interacting with internal services. This is only exploitable if OAuth2 avatar synchronization is enabled and the attacker can control their own picture claim in the authentication provider.

CVSS Base Scores

version 4.0
version 3.1