CVE-2026-26247

Discovered by AISLEPUBLISHEDCWE-284

Description

An OAuth2 PKCE flaw in Gitea where code_challenge_method=S256 was not handled correctly during authorization, causing the S256 method not to be persisted and weakening or bypassing the expected PKCE verifier enforcement during the token exchange.

CVSS Base Scores

CVSS v3.1(Primary)
8.1

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Affected Products

VendorProductVersionStatus
GiteaGitea< 1.25.5affected

Credits

  • Aisle Research(reporter)

References