Unrated severityNVD Advisory· Published Jul 3, 2026· Updated Jul 7, 2026
Gitea OAuth2 authorization codes lack expiry and reuse enforcement
CVE-2026-26232
Description
Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use behavior during token exchange.
Affected products
1Patches
Vulnerability mechanics
References
4- github.com/go-gitea/gitea/pull/36797mitrepatch
- github.com/go-gitea/gitea/pull/36851mitrepatch
- blog.gitea.com/release-of-1.25.5/mitrerelease-notes
- github.com/go-gitea/gitea/releases/tag/v1.25.5mitrerelease-notes
News mentions
0No linked articles in our index yet.