CVE-2026-20779
Gitea Gitea Open Source Git Server
Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a valid TOTP code to be accepted more than once across web two-factor authentication flows and the Basic Auth X-Gitea-OTP path.
- CVSS
- 7.1
- EPSS
- 0.40% 32.6% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.04