PT-2026-107291 · Gitea · Gitea
CVE-2026-101023
·
Published
2026-10-06
·
Updated
2026-10-06
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Gitea's OAuth2 token endpoint verified the signature and grant of a token submitted with the
refresh token grant type, but not that the token was a refresh token. An unexpired access token for the same OAuth2 application and grant could be exchanged for a new access token and refresh token. Whoever holds such an access token could keep access beyond the token's original lifetime. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gitea