


Perceptive Security
SOC/SIEM Consultancy

Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fet…
Published:
5 August 2026 at 00:00:00
Alert date:
6 August 2026 at 00:02:16
Source:
nvd.nist.gov
Web Technologies, Data Breach & Exfiltration, Identity & Access
Gitea versions prior to 1.27.0 are affected by a server-side request forgery (SSRF) vulnerability that allows authenticated attackers to bypass existing SSRF protections. The flaw exists in HTTP fetch operations within migration and OAuth avatar code paths that use Go's default http.Get without a custom DialContext. Attackers can supply arbitrary URLs through release asset download URLs, pull-request patch URLs, or OAuth avatar endpoints. This can be exploited to reach internal services, cloud instance-metadata endpoints, or read local files including application configuration files containing database credentials and signing secrets. Exfiltrated content can be persisted as migration release assets for later retrieval, making data exfiltration stealthy and persistent. The vulnerability requires authentication but poses a high risk to organizations hosting Gitea internally or in cloud environments. A fix is available in Gitea 1.27.0, and affected users are strongly advised to upgrade immediately.
Technical details
Mitigation steps:
Affected products:
Gitea prior to 1.27.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-34966
https://github.com/go-gitea/gitea
https://github.com/go-gitea/gitea/commit/b969123b7fac51c88daab5cb64e5b2f4abd53288
https://github.com/go-gitea/gitea/security/advisories/GHSA-2wm4-vwp6-v7xc
https://www.vulncheck.com/advisories/gitea-prior-to-ssrf-via-migration-uri-fetch-bypass
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
