CVE-2026-26247
Gravedad CVSS v3.1:
CRÍTICA
Tipo:
CWE-284
Control de acceso incorrecto
Fecha de publicación:
03/07/2026
Última modificación:
07/07/2026
Descripción
*** Pendiente de traducción *** Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check.
Impacto
Puntuación base 3.x
9.10
Gravedad 3.x
CRÍTICA



