CVE-2026-26247
published 2026-07-03CVE-2026-26247: Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected…
PriorityP353critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.38%
31.3th percentile
Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gitea | gitea_open_source_git_server | < 1.25.5 | 1.25.5 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Gitea up to 1.25.4 access control
vuldb·2026-07-04
CVE-2026-26247 [CRITICAL] Gitea up to 1.25.4 access control
A vulnerability was found in Gitea up to 1.25.4. It has been rated as critical. Impacted is an unknown function. The manipulation leads to improper access controls.
This vulnerability is documented as CVE-2026-26247. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.
GHSA
Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check.
ghsa_unreviewed·2026-07-03
CVE-2026-26247 CWE-284 Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check.
Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check.
No detection rules found.
No public exploits indexed.
2026-07-03
Published