<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 15:16:02 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-15781</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-15781</link>
      <description>bdu:2026-15781</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-15781</guid>
    </item>
    <item>
      <title>EUVD-2026-352807</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352807</link>
      <description>EUVD-2026-352807</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352807</guid>
    </item>
    <item>
      <title>fkie_cve-2026-23603</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-23603</link>
      <description>&lt;p&gt;Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-23603</guid>
    </item>
    <item>
      <title>GHSA-x77v-q46j-393g — Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x77v-q46j-393g</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;### Summary
When `[oauth2_client] UPDATE_AVATAR = true` is enabled, Gitea fetches the avatar URL received from an OAuth2/OIDC provider using Go&amp;#39;s default HTTP client. The URL comes from the user&amp;#39;s OAuth/OIDC avatar value, commonly the OIDC `picture` claim.&lt;/p&gt;
&lt;p&gt;The affected code path calls `http.Get(url)` without applying outbound host or IP restrictions. A low-privileged user who can influence their own `picture` claim under an already-configured OAuth2/OIDC source can cause the Gitea server to make arbitrary outbound HTTP GET requests. This includes requests to loopback addresses, RFC 1918 private network addresses, and IPv4 link-local addresses such as `169.254.169.254`.&lt;/p&gt;
&lt;p&gt;This is a blind SSRF by default. Impact can increase in deployments where the Gitea host can reach cloud metadata services, localhost-only services, or internal services that return valid image data.&lt;/p&gt;
&lt;p&gt;### Details
The vulnerable sink is in `routers/web/auth/oauth.go`:&lt;/p&gt;
&lt;p&gt;```go
func oauth2UpdateAvatarIfNeed(ctx *context.Context, url string, u *user_model.User) {
    if setting.OAuth2Client.UpdateAvatar &amp;amp;&amp;amp; len(url) &amp;gt; 0 {
        resp, err := http.Get(url)
        if err == nil {
            defer func() { _ = resp.Body.Close() }()
        }
        if err == nil &amp;amp;&amp;amp; resp.StatusCode == http.StatusOK {
            data, err := io.ReadAll(io.LimitReader(resp.Body, setting.Avatar.MaxFileSize+1))
            if err == nil &amp;amp;&amp;amp; int64(len(data)) &amp;lt;= setting.Avatar.MaxFileSize {
                _ = user_service.UploadAvatar(…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;### Summary
When `[oauth2_client] UPDATE_AVATAR = true` is enabled, Gitea fetches the avatar URL received from an OAuth2/OIDC provider using Go&amp;#39;s default HTTP client. The URL comes from the user&amp;#39;s OAuth/OIDC avatar value, commonly the OIDC `picture` claim.&lt;/p&gt;
&lt;p&gt;The affected code path calls `http.Get(url)` without applying outbound host or IP restrictions. A low-privileged user who can influence their own `picture` claim under an already-configured OAuth2/OIDC source can cause the Gitea server to make arbitrary outbound HTTP GET requests. This includes requests to loopback addresses, RFC 1918 private network addresses, and IPv4 link-local addresses such as `169.254.169.254`.&lt;/p&gt;
&lt;p&gt;This is a blind SSRF by default. Impact can increase in deployments where the Gitea host can reach cloud metadata services, localhost-only services, or internal services that return valid image data.&lt;/p&gt;
&lt;p&gt;### Details
The vulnerable sink is in `routers/web/auth/oauth.go`:&lt;/p&gt;
&lt;p&gt;```go
func oauth2UpdateAvatarIfNeed(ctx *context.Context, url string, u *user_model.User) {
    if setting.OAuth2Client.UpdateAvatar &amp;amp;&amp;amp; len(url) &amp;gt; 0 {
        resp, err := http.Get(url)
        if err == nil {
            defer func() { _ = resp.Body.Close() }()
        }
        if err == nil &amp;amp;&amp;amp; resp.StatusCode == http.StatusOK {
            data, err := io.ReadAll(io.LimitReader(resp.Body, setting.Avatar.MaxFileSize+1))
            if err == nil &amp;amp;&amp;amp; int64(len(data)) &amp;lt;= setting.Avatar.MaxFileSize {
                _ = user_service.UploadAvatar(…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x77v-q46j-393g</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2304 — Gitea: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</guid>
    </item>
  </channel>
</rss>
