Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use behavior during token exchange.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 03 Jul 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use behavior during token exchange. | |
| Title | Gitea OAuth2 authorization codes lack expiry and reuse enforcement | |
| Weaknesses | CWE-294 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Gitea
Published:
Updated: 2026-07-03T20:19:34.473Z
Reserved: 2026-03-03T03:25:28.619Z
Link: CVE-2026-26232
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses