CVE-2026-73278
Gitea WebAuthn bypass during OAuth and OIDC sign-in
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Gitea's OAuth2 and OpenID Connect sign-in paths do not require a WebAuthn challenge when WebAuthn is the account's only configured second factor. A party able to authenticate through the affected external identity flow can obtain a full session without the passkey verification enforced during password login. One affected path can also persist an external identity link, extending the compromise beyond the initial session; accounts with TOTP configured are outside the reported WebAuthn-only scenario.
| CWE | CWE-287 |
| Vendor | gitea |
| Product | gitea |
| Published | Oct 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for gitea gitea
Be the first to know when new unknown vulnerabilities affecting gitea gitea are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Gitea / Gitea
1.16.0 โค 1.27.1
References
github.com: https://github.com/go-gitea/gitea/security/advisories/GHSA-92j2-6qcg-c28c blog.gitea.com: https://blog.gitea.com/release-of-1.27.2/ github.com: https://github.com/go-gitea/gitea/pull/38805 github.com: https://github.com/go-gitea/gitea/pull/38810 github.com: https://github.com/go-gitea/gitea/releases/tag/v1.27.2
Credits
๐ https://github.com/MindflareX ๐ https://github.com/AdamKorcz ๐ https://github.com/jaeyoon-kim-dev