CVE-2026-34966: Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in mig
Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default http.Get without a custom DialContext. Attackers can supply arbitrary URLs through release asset download URLs, pull-request patch URLs, or OAuth avatar endpoints to reach internal services, cloud instance-metadata endpoints, or read local files such as the application configuration containing database credentials and signing secrets, with exfiltrated content persisted as migration release assets for later retrieval.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-34966
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-349660.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-34966 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for Gitea
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- medium[NEW] [medium] Gitea: Multiple Vulnerabilities Enable Information Disclosurecert-bund · 2026-08-06
- high[NEW] [high] Gitea: Vulnerability enables information disclosure and code executioncert-bund · 2026-08-03
- high[NEW] [high] Gitea: Vulnerability allows code executioncert-bund · 2026-07-29
- highGHSA-gx3v-q759-g323: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OT…ghsa · 2026-07-21
- mediumGHSA-fq2p-5p22-8g6j: Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission End…ghsa · 2026-07-21
- mediumGHSA-2wm4-vwp6-v7xc: Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and…ghsa · 2026-07-21
More from NVD Recent CVEs
- criticalCVE-2026-70332: Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an unauthorized attac…2026-08-07
- criticalCVE-2026-68823: Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacke…2026-08-07
- highCVE-2026-65668: Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to eleva…2026-08-07
- criticalCVE-2026-65667: Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges…2026-08-07
- criticalCVE-2026-63508: Missing authentication for critical function in Microsoft Planetary Computer Pro allows an una…2026-08-07