CVE-2026-26247EPSS p31.0%

CVE-2026-26247CVE-2026-26247

Description

Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check.

Scoring

CVSS 9.1 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS0.38% probability of exploitation · percentile 31.0% · 2026-08-17T12:03:47Z
Last modified2026-07-07
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.