CVE-2026-20779 UNKNOWN

CVE-2026-20779

Published: 2026-07-03

Description

Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a valid TOTP code to be accepted more than once across web two-factor authentication flows and the Basic Auth X-Gitea-OTP path.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…