CVE-2026-20779Patch

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a valid TOTP code to be accepted more than once across web two-factor authentication flows and the Basic Auth X-Gitea-OTP path.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-294

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-05: 1Patch / Workaround · 2026-07-05: 1Technical Details · 2026-07-05: 107-05
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    #CVE-2026-20779 - Supply chain attack risk in #Gitea. TOTP reuse flaw bypasses 2FA. #CVSS 7.1. Update to 1.26.3 or later immediately. #CVEAlert #SecurityAlert #cybersecuritytips #cybersecurity #devops #developers #devsecops #infosec #sysadmin More info: https://www.valtersit.com/cve/CVE-2026-20779

    Post summary

    The tweet alerts on a Gitea 2FA bypass flaw (CVE-2026-20779), urges an update to 1.26.3 or later, and links to additional information.

    0000045
    972 followersView on X

Explore more