CVE-2026-26232: Gitea OAuth2 authorization codes lack expiry and reuse enforcement
Published Jul 3, 2026
·Updated
Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use behavior during token exchange.
Affected Software
1 affected component
Gitea Gitea<1.25.5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Giteato a version that resolves this vulnerability.Fixed in 1.25.5
Event History
Jul 3, 2026
CVE Published
via MITRE·08:19 PM
Data Sourced
via MITRE·08:19 PM
DescriptionWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-26232?
CVE-2026-26232 has a risk rating of 47, indicating a significant vulnerability.
2
What products are affected by CVE-2026-26232?
Gitea versions prior to 1.25.5 are affected by CVE-2026-26232.
3
How do I fix CVE-2026-26232?
To mitigate CVE-2026-26232, upgrade Gitea to version 1.25.5 or later.
4
What are the implications of CVE-2026-26232?
CVE-2026-26232 allows unauthorized reuse of OAuth2 authorization codes due to lack of expiry enforcement.
5
What behavior is not enforced in CVE-2026-26232?
CVE-2026-26232 does not enforce single-use behavior for OAuth2 authorization codes during token exchange.