Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-26232: Gitea OAuth2 Codes Not Expired or Reused
CVE-2026-26232
CVE-2026-26232
Summary
Gitea versions before 1.25.5 may allow unauthorized access if an attacker intercepts an OAuth2 authorization code. This is because Gitea does not enforce a time limit for the code to be used and does not prevent the code from being reused. To fix this, update to Gitea version 1.25.5 or later.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| gitea | gitea open source git server | < 1.25.5 |
Original title
Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use behavior during token exchange.
Original description
Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use behavior during token exchange.
Vulnerability type
CWE-294
Published: 3 Jul 2026 · Updated: 23 Jul 2026 · First seen: 3 Jul 2026