๐Ÿ” CVE Alert

CVE-2026-73278

UNKNOWN 0.0

Gitea WebAuthn bypass during OAuth and OIDC sign-in

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Gitea's OAuth2 and OpenID Connect sign-in paths do not require a WebAuthn challenge when WebAuthn is the account's only configured second factor. A party able to authenticate through the affected external identity flow can obtain a full session without the passkey verification enforced during password login. One affected path can also persist an external identity link, extending the compromise beyond the initial session; accounts with TOTP configured are outside the reported WebAuthn-only scenario.

CWE CWE-287
Vendor gitea
Product gitea
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for gitea gitea

Be the first to know when new unknown vulnerabilities affecting gitea gitea are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Gitea / Gitea
1.16.0 โ‰ค 1.27.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/go-gitea/gitea/security/advisories/GHSA-92j2-6qcg-c28c blog.gitea.com: https://blog.gitea.com/release-of-1.27.2/ github.com: https://github.com/go-gitea/gitea/pull/38805 github.com: https://github.com/go-gitea/gitea/pull/38810 github.com: https://github.com/go-gitea/gitea/releases/tag/v1.27.2

Credits

๐Ÿ” https://github.com/MindflareX ๐Ÿ” https://github.com/AdamKorcz ๐Ÿ” https://github.com/jaeyoon-kim-dev