Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-26247

Опубликовано: 03 июл. 2026
Источник: debian
EPSS Низкий

Описание

Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gitearemovedpackage

EPSS

Процентиль: 31%
0.00379
Низкий

Связанные уязвимости

CVSS3: 9.1
nvd
около 2 месяцев назад

Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check.

CVSS3: 9.1
github
около 2 месяцев назад

Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check.

EPSS

Процентиль: 31%
0.00379
Низкий