CVE-2026-23603 Blast Radius

LOW • CVSS 3.1Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim ### Summary When `[oauth2_client] UPDATE_AVATAR = true` is enab

Is Your Infrastructure Using These Packages?

EchelonGraph automatically scans your cloud infrastructure and SBOMs to map your exposure to vulnerabilities like CVE-2026-23603.