Количество 3
Количество 3
CVE-2026-20779
Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a valid TOTP code to be accepted more than once across web two-factor authentication flows and the Basic Auth X-Gitea-OTP path.
CVE-2026-20779
Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforce ...
GHSA-gx3v-q759-g323
Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-20779 Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a valid TOTP code to be accepted more than once across web two-factor authentication flows and the Basic Auth X-Gitea-OTP path. | CVSS3: 7.1 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-20779 Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforce ... | CVSS3: 7.1 | 0% Низкий | около 2 месяцев назад | |
GHSA-gx3v-q759-g323 Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface | CVSS3: 7.1 | 0% Низкий | около 1 месяца назад |
Уязвимостей на страницу