Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-26247: Gitea OAuth Token Exchange Without Verification
CVE-2026-26247
CVE-2026-26247
Summary
Gitea versions before 1.25.5 have a security issue that could allow unauthorized access to tokens. This is a concern because it could lead to attackers getting access to sensitive information. To fix this, update Gitea to version 1.25.5 or later.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| gitea | gitea open source git server | < 1.25.5 |
Original title
Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check.
Original description
Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check.
Vulnerability type
CWE-284
Improper Access Control
Published: 3 Jul 2026 · Updated: 23 Jul 2026 · First seen: 3 Jul 2026