GHSA-5v69-g2m3-3hq3CriticalCVSS 9.1

Gitea OAuth2 authorization codes can be reused after expiry

Published
July 3, 2026
Last Modified
September 1, 2026

🔗 CVE IDs covered (1)

📋 Description

Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use behavior during token exchange.

🎯 Affected products1

  • go/code.gitea.io/gitea:< 1.25.5

🔗 References (8)