PT-2026-65380 · Go · Gitea.Dev

Published

2026-07-27

·

Updated

2026-07-27

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

GO-2026-6083

Affected Products

Gitea.Dev