VDB
Sign up
CRITICAL9.1

GHSA-m5ch-ppfx-xv3v

Gitea OAuth2 PKCE S256 verifier bypass

Quick fix

GHSA-m5ch-ppfx-xv3v — code.gitea.io/gitea: upgrade to the fixed version with the command below.

go get code.gitea.io/gitea@v1.25.5

Details

Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/code.gitea.io/gitea
Introduced in: 0Fixed in: 1.25.5
Fixgo get code.gitea.io/gitea@v1.25.5

References