Description
Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check.
Related CPE's
Could not find any relations
References
Weaknesses
88ee5874-cf24-4952-aea0-31affedb7ff2
Secondary
CWE-284
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
9.1 · Critical
Information
Source identifier
88ee5874-cf24-4952-aea0-31affedb7ff2
Vulnerability status
Deferred
Published
2026-07-03T21:16:58.417Z
3 months agoLast modified
2026-07-07T18:16:37.327Z
3 months ago