Summary
CVE-2026-26232 is a critical authentication bypass vulnerability in Gitea (Open Source Git Server), affecting all versions before 1.25.5. The flaw arises from Gitea’s failure to consistently enforce OAuth2 authorization code expiry and single-use behavior during token exchange — meaning an attacker who obtains an authorization code, including one that is expired or has already been used, can replay it to obtain valid OAuth2 access tokens. The vulnerability carries a CVSS v3.1 score of 9.1 (Critical) and is network-exploitable with no authentication or user interaction required.
Technical details
- Root cause: The
ValidUntilexpiration timestamp for OAuth2 authorization codes existed in Gitea’s data model but was never actually validated during the token exchange process. As noted in the remediation pull request: "The OAuth2 code expiration time has never been used" prior to this fix. Concurrent or repeated attempts to redeem the same code were also not detected, violating RFC 6749 security expectations for authorization code flows. - Trigger conditions: An attacker who intercepts or otherwise obtains a Gitea OAuth2 authorization code — even one that is expired or has already been exchanged — can replay it against the token endpoint to receive valid access tokens for the associated account.
- Attack vector: Fully remote and network-accessible; no prior authentication, account privileges, or user interaction are required (AV:N/AC:L/PR:N/UI:N).
- Impact: Successful exploitation allows an attacker to obtain valid OAuth2 tokens and gain unauthorized access to the targeted Gitea account, including its repositories, source code, secrets, and configuration — with high confidentiality and integrity impact (C:H/I:H). Classified under CWE-294: Authentication Bypass by Capture-Replay.
Affected software
- Gitea Open Source Git Server — all versions before 1.25.5
Severity
- CVSS v3.1 Base Score: 9.1 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Mitigation and recommended actions
- Immediate: Upgrade to Gitea 1.25.5 or later. The fix was implemented in pull requests #36797 and #36851, which enforce authorization code expiration checks and detect concurrent or repeated code redemption attempts.
- Gitea instances with OAuth2 enabled and exposed to the internet should be treated as the highest patching priority.
- If immediate patching is not feasible, consider disabling OAuth2 application integrations and restricting network access to the Gitea token exchange endpoint as a temporary mitigation.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

