Junglewise Threat Intelligence

CVE-2026-26247: Gitea OAuth2 PKCE S256 verifier bypass

CVE-2026-26247 · Severity: critical · CVSS 9.1 · Published 2026-07-03

Technologies: code.gitea.io/gitea (Go), Gitea. Vendors: Go, Gitea.

Executive brief

Gitea is a self-hosted Git repository management platform that uses OAuth2 to delegate user authentication and authorization. This vulnerability allows attackers to bypass the PKCE (Proof Key for Code Exchange) S256 security mechanism, which is designed to prevent token interception attacks. An attacker could exploit this to obtain valid access tokens without proper verification, potentially gaining unauthorized access to user accounts and repository data.

Technical details

The vulnerability exists in Gitea's OAuth2 provider implementation where the PKCE S256 (SHA-256) challenge method is not properly persisted during the authorization code flow. PKCE is a security extension to OAuth2 that requires clients to prove knowledge of a secret verifier during token exchange, protecting against authorization code interception attacks. Attackers without network access privileges can initiate OAuth2 flows and exchange authorization codes for tokens without providing the correct PKCE verifier, due to the missing or incorrect validation. This requires no user interaction and affects confidentiality and integrity of authenticated sessions. The vulnerability affects Gitea versions before 1.25.5; patches are available in version 1.25.5 and later.

Affected products

  • Gitea Gitea before 1.25.5

Timeline

  • 2026-07-03: disclosed: Published to GitHub Advisory Database
  • 2026-03-13: patched: Gitea 1.25.5 released with fix
  • 2026-01-27: other: Fix merged in pull request #36462

References

Related threats