A AegiFlow
CRITICALCVSS 9.1EPSS 0.5%

CVE-2026-26247

Gitea OAuth2 PKCE S256 verifier bypass

Published
2026-07-03
Modified
2026-09-01
EPSS percentile
41%
Aliases
GHSA-m5ch-ppfx-xv3v
Sources
github-advisory

Summary

Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check.

Affected packages

EcosystemPackageAffected versionsFixed versions
Gocode.gitea.io/gitea1.25.5

Remediation: Upgrade to 1.25.5 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.