Vulnerability Report: GO-2026-6057
- CVE-2026-20779, GHSA-gx3v-q759-g323
- Affects: code.gitea.io/gitea
- Published: Jul 22, 2026
Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
For detailed information about this vulnerability, visit https://github.com/go-gitea/gitea/security/advisories/GHSA-gx3v-q759-g323 or https://nvd.nist.gov/vuln/detail/CVE-2026-20779.
Affected Packages
-
PathVersionsSymbols
Aliases
References
- https://github.com/go-gitea/gitea/security/advisories/GHSA-gx3v-q759-g323
- https://nvd.nist.gov/vuln/detail/CVE-2026-20779
- https://blog.gitea.com/release-of-1.26.3-and-1.26.4
- https://github.com/go-gitea/gitea/commit/99f8b3d9a1d32f4c39828e07971455a18191e0b9
- https://github.com/go-gitea/gitea/pull/38151
- https://github.com/go-gitea/gitea/releases/tag/v1.26.3
- https://vuln.go.dev/ID/GO-2026-6057.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.