CVE-2026-101023 PUBLISHED

Gitea OAuth2 refresh token grant accepts access tokens

Assigner: Gitea
Reserved: 04.10.2026 Published: 06.10.2026 Updated: 06.10.2026

Gitea's OAuth2 token endpoint verified the signature and grant of a token submitted with the refresh_token grant type, but not that the token was a refresh token. An unexpired access token for the same OAuth2 application and grant could be exchanged for a new access token and refresh token. Whoever holds such an access token could keep access beyond the token's original lifetime.

Product Status

Vendor Gitea
Product Gitea
Versions Default: unaffected
  • affected from 0 to 28.0.0 (incl.)

Credits

  • https://github.com/rezmoss reporter
  • https://github.com/manus-use reporter
  • https://github.com/danieltk76 reporter
  • https://github.com/gigioneggiando reporter
  • https://github.com/DshtAnger reporter
  • https://github.com/manus-pi reporter
  • https://github.com/silverwind remediation developer
  • https://github.com/bircni remediation developer

References