Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-26247

Опубликовано: 03 июл. 2026
Источник: nvd
CVSS3: 9.1
EPSS Низкий

Описание

Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check.

EPSS

Процентиль: 31%
0.00379
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 9.1
debian
около 2 месяцев назад

Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 chall ...

CVSS3: 9.1
github
около 2 месяцев назад

Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check.

EPSS

Процентиль: 31%
0.00379
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-284