CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-34966: Gitea 0 through 1.26.4

CVE-2026-34966. CVSS 3.1 base score 7.6 (HIGH, Vendor/CNA). EPSS 0.00389 (percentile 0.30797), scored 2026-10-06.

Affected technology

Gitea · 0 through 1.26.4
Gitea

Description’s affected range: prior to 1.27.0

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · High privileges required · No user interaction required

What an attacker can do

Authenticated attackers can bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default http.Get without a custom DialContext. Vendor/CNA’s CVSS 4.0 assessment (base score 8.3/10) rates confidentiality impact as high; integrity impact as low; availability impact as none.

Published

CWE
CWE-918
CCR priority
30.5 /100 (P4)
CVSS 3.1
7.6 /10 · CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N · Vendor/CNA
EPSS
0.00389 · percentile 0.30913 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-34966.html