CVE-2026-26247
Gitea Gitea Open Source Git Server 취약점
Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check.
- 대응 우선순위
- 점검
- CVSS
- 9.1
- EPSS
- 0.38% 백분위 30.7% · 2026.08.03 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.07.04