Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-34966

Опубликовано: 05 авг. 2026
Источник: redhat
CVSS3: 7.6
EPSS Низкий

Описание

Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default http.Get without a custom DialContext. Attackers can supply arbitrary URLs through release asset download URLs, pull-request patch URLs, or OAuth avatar endpoints to reach internal services, cloud instance-metadata endpoints, or read local files such as the application configuration containing database credentials and signing secrets, with exfiltrated content persisted as migration release assets for later retrieval.

A flaw was found in Gitea. This server-side request forgery (SSRF) vulnerability allows authenticated attackers to bypass existing protections. By manipulating HTTP fetch operations during migrations or OAuth avatar processing, an attacker can force the Gitea server to make requests to arbitrary internal or external URLs. This could lead to the disclosure of sensitive information, such as database credentials or internal network details, which can then be retrieved by the attacker.

Отчет

This is an important server-side request forgery (SSRF) bypass vulnerability in Gitea that allows authenticated attackers to access internal services or local files. However, Red Hat products are not affected by this vulnerability as they do not run Gitea servers. Red Hat OpenShift Pipelines only imports the structs and json modules from code.gitea.io/gitea for webhook / typing purposes.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Pipelinesopenshift-pipelines-clientNot affected
OpenShift Pipelinesopenshift-pipelines/pipelines-cli-tkn-rhel9Not affected
OpenShift Pipelinesopenshift-pipelines/pipelines-opc-rhel9Not affected
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-cli-rhel9Not affected
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-controller-rhel9Not affected
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-watcher-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-918
https://bugzilla.redhat.com/show_bug.cgi?id=2511770code.gitea.io/gitea: Gitea: Information disclosure via Server-Side Request Forgery (SSRF) bypass

EPSS

Процентиль: 24%
0.00314
Низкий

7.6 High

CVSS3

Связанные уязвимости

CVSS3: 7.6
ubuntu
6 дней назад

Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default http.Get without a custom DialContext. Attackers can supply arbitrary URLs through release asset download URLs, pull-request patch URLs, or OAuth avatar endpoints to reach internal services, cloud instance-metadata endpoints, or read local files such as the application configuration containing database credentials and signing secrets, with exfiltrated content persisted as migration release assets for later retrieval.

CVSS3: 7.6
nvd
6 дней назад

Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default http.Get without a custom DialContext. Attackers can supply arbitrary URLs through release asset download URLs, pull-request patch URLs, or OAuth avatar endpoints to reach internal services, cloud instance-metadata endpoints, or read local files such as the application configuration containing database credentials and signing secrets, with exfiltrated content persisted as migration release assets for later retrieval.

CVSS3: 7.6
debian
6 дней назад

Gitea prior to 1.27.0 contains a server-side request forgery vulnerabi ...

CVSS3: 7.6
github
6 дней назад

Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default http.Get without a custom DialContext. Attackers can supply arbitrary URLs through release asset download URLs, pull-request patch URLs, or OAuth avatar endpoints to reach internal services, cloud instance-metadata endpoints, or read local files such as the application configuration containing database credentials and signing secrets, with exfiltrated content persisted as migration release assets for later retrieval.

EPSS

Процентиль: 24%
0.00314
Низкий

7.6 High

CVSS3