CVE-2026-26247
Discovered by AISLEPUBLISHEDCWE-284
Description
An OAuth2 PKCE flaw in Gitea where code_challenge_method=S256 was not handled correctly during authorization, causing the S256 method not to be persisted and weakening or bypassing the expected PKCE verifier enforcement during the token exchange.
CVSS Base Scores
CVSS v3.1(Primary)
8.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Affected Products
| Vendor | Product | Version | Status |
|---|---|---|---|
| Gitea | Gitea | < 1.25.5 | affected |
Credits
- Aisle Research(reporter)