PT-2026-107291 · Gitea · Gitea

CVE-2026-101023

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Gitea's OAuth2 token endpoint verified the signature and grant of a token submitted with the refresh token grant type, but not that the token was a refresh token. An unexpired access token for the same OAuth2 application and grant could be exchanged for a new access token and refresh token. Whoever holds such an access token could keep access beyond the token's original lifetime.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-101023

Affected Products

Gitea