CVE-2026-34966 | Gitea up to 1.26.4 Migration/OAuth Avatar http.Get server-side request forgery
A vulnerability classified as problematic was found in Gitea up to 1.26.4. The affected element is the function http.Get of the component Migration/OAuth Avatar. Such manipulation leads to server-side request forgery.
This vulnerability is traded as CVE-2026-34966. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.VulDB Recent EntriesRead More