CVE-2026-34966
Last modified
CVE-2026-34966 is a high-severity vulnerability rated 7.6/10 on the CVSS scale. Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default http.Get without a custom DialContext. Attackers can supply arbitrary URLs through release asset download URLs, pull-request patch URLs, or OAuth avatar endpoints to reach internal services, cloud instance-metadata endpoints, or read local files such as the application configuration containing database credentials and signing secrets, with exfiltrated content persisted as migration release assets for later retrieval.. EPSS estimates a 0.43% chance of exploitation in the next 30 days.
Description
Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default http.Get without a custom DialContext. Attackers can supply arbitrary URLs through release asset download URLs, pull-request patch URLs, or OAuth avatar endpoints to reach internal services, cloud instance-metadata endpoints, or read local files such as the application configuration containing database credentials and signing secrets, with exfiltrated content persisted as migration release assets for later retrieval.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Gitea | Gitea | <= 1.26.4 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-34966?
How severe is CVE-2026-34966?
How do I fix CVE-2026-34966?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-34960barebox prior to version 2026.04.0 contains an out-of-bounds…7.1
- CVE-2026-34961barebox prior to version 2026.04.0 contains out-of-bounds re…7.7
- CVE-2026-34962barebox version prior to 2026.04.0 contains a denial-of-serv…5.5
- CVE-2026-34963barebox version prior to 2026.04.0 contains multiple memory-…7.8
- CVE-2026-34964Adminer before 5.5.0 contains a server-side request forgery …5.8
- CVE-2026-34965Cockpit CMS contains an authenticated remote code execution …8.8
- CVE-2026-34967Adminer versions 5.3.0 through 5.4.2 with the sql-log plugin…5.4
- CVE-2026-34968Adminer before 5.4.3 contains an arbitrary file deletion vul…8.1
- CVE-2026-34969Nhost is an open source Firebase alternative with GraphQL. P…7.5
- CVE-2026-3497Vulnerability in the OpenSSH GSSAPI delta included in variou…7.5
- CVE-2026-34970Mantis Bug Tracker (MantisBT) is an open source issue tracke…5.3
- CVE-2026-34971Wasmtime is a runtime for WebAssembly. From 32.0.0 to before…9
Are you affected by CVE-2026-34966?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
