Junglewise Threat Intelligence

CVE-2026-20779: Gitea TOTP single-use enforcement defect in 2FA flows

CVE-2026-20779 · Severity: high · CVSS 7.1 · Published 2026-07-03

Technologies: code.gitea.io/gitea (Go), Gitea. Vendors: Go, Gitea.

Executive brief

Gitea, a popular self-hosted Git service, contains two vulnerabilities in its two-factor authentication (2FA) implementation. These flaws allow an attacker who has already obtained a user's password to bypass the 'one-time' requirement of security codes, potentially gaining unauthorized access to the web interface or API. This could lead to unauthorized code access, data theft, or the creation of persistent access tokens.

Technical details

Gitea suffers from two distinct TOTP reuse vulnerabilities. First, a Time-of-Check Time-of-Use (TOCTOU) race condition exists in the web 2FA login and password reset flows because the validation and update of the 'LastUsedPasscode' are not atomic. An attacker can submit parallel requests to authenticate multiple sessions with a single OTP. Second, the Basic-Auth API and Git-over-HTTPS paths fail to perform any 'LastUsedPasscode' check, allowing a single OTP to be replayed indefinitely within the 60-90 second validity window. These issues allow an attacker with a victim's password and a captured OTP to bypass 2FA protections. The vulnerabilities are patched in version 1.26.3.

Affected products

  • Gitea Gitea >= 1.5.0, < 1.26.3

Timeline

  • 2026-06-21: disclosed: Initial disclosure on GitHub Advisories
  • 2026-07-21: advisory: Advisory updated and published
  • 2026-07-21: patched: Fix released in version 1.26.3

References

Related threats