{"id":"CVE-2026-34966","aliases":["CVE-2026-59765","GHSA-2wm4-vwp6-v7xc","GO-2026-6039"],"url":"https://o3.security/vulnerability/CVE-2026-34966","summary":"Gitea prior to 1.27.0 SSRF via Migration URI Fetch Bypass","details":"Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default http.Get without a custom DialContext. Attackers can supply arbitrary URLs through release asset download URLs, pull-request patch URLs, or OAuth avatar endpoints to reach internal services, cloud instance-metadata endpoints, or read local files such as the application configuration containing database credentials and signing secrets, with exfiltrated content persisted as migration release assets for later retrieval.","published":"2026-08-05T20:28:57.744Z","modified":"2026-08-15T04:06:56.312692724Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"code.gitea.io/gitea","fixedVersion":"1.27.0"}],"fix":{"url":"https://github.com/go-gitea/gitea/commit/b969123b7fac51c88daab5cb64e5b2f4abd53288","label":"go-gitea/gitea@b969123"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/34xxx/CVE-2026-34966.json"},{"type":"ADVISORY","url":"https://github.com/go-gitea/gitea/security/advisories/GHSA-2wm4-vwp6-v7xc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34966"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/gitea-prior-to-ssrf-via-migration-uri-fetch-bypass"},{"type":"FIX","url":"https://github.com/go-gitea/gitea/commit/b969123b7fac51c88daab5cb64e5b2f4abd53288"},{"type":"PACKAGE","url":"https://github.com/go-gitea/gitea"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-15T04:06:56.312692724Z"}}