Session Hijacking Vulnerability in Gitea's OAuth2 and OpenID Connect Authentication
CVE-2026-73278
What is CVE-2026-73278?
Gitea has identified a weakness in its OAuth2 and OpenID Connect sign-in mechanisms. Specifically, when users configure WebAuthn as their only second-factor authentication method, the system fails to mandate a WebAuthn challenge during authentication. This gap allows an attacker who gains access through vulnerable external identity flows to establish a complete session on behalf of the user without the necessary passkey verification imposed during regular password-based logins. Moreover, this vulnerability may facilitate the persistence of an external identity link, consequently extending the potential security compromise across multiple sessions. It is noteworthy that accounts utilizing Time-based One-Time Password (TOTP) are exempt from this specific issue.
Affected Version(s)
Gitea 1.16.0 <= 1.27.1
