Gitea · Gitea · CVE-2026-20779
**Name of the Vulnerable Software and Affected Versions**
Gitea versions 1.5.0 through 1.26.2
**Description**
A defect in the Time-based One-Time Password (TOTP) single-use enforcement allows a valid TOTP code to be accepted multiple times. This issue affects web two-factor authentication flows and the Basic Auth `X-Gitea-OTP` path, potentially allowing an attacker to bypass two-factor authentication.
**Recommendations**
Update Gitea to version 1.26.3 or later.