GHSA-m5ch-ppfx-xv3v

Suggest an improvement
Source
https://github.com/advisories/GHSA-m5ch-ppfx-xv3v
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-m5ch-ppfx-xv3v/GHSA-m5ch-ppfx-xv3v.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-m5ch-ppfx-xv3v
Aliases
Published
2026-07-03T21:31:37Z
Modified
2026-09-02T19:41:26.264195457Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
Gitea OAuth2 PKCE S256 verifier bypass
Details

Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check.

Database specific
{
    "cwe_ids": [
        "CWE-284"
    ],
    "nvd_published_at": "2026-07-03T21:16:58Z",
    "github_reviewed": true,
    "severity": "CRITICAL",
    "github_reviewed_at": "2026-09-01T17:23:03Z"
}
References

Affected packages

Go / code.gitea.io/gitea

Package

Name
code.gitea.io/gitea
View open source insights on deps.dev
Purl
pkg:golang/code.gitea.io/gitea

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.25.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-m5ch-ppfx-xv3v/GHSA-m5ch-ppfx-xv3v.json"