OAuth2 Token Vulnerability in Gitea by Gitea
CVE-2026-101023

Currently unrated

Key Information:

Vendor

Gitea

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-101023?

A vulnerability in Gitea's OAuth2 token endpoint allows an attacker to exchange a valid access token for a new access and refresh token without proper verification of the token type. This oversight could let unauthorized users maintain access beyond their original session, posing a significant threat to sensitive data and user privacy. It is crucial for users of affected versions to update their systems promptly.

Affected Version(s)

Gitea 0 <= 28.0.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

https://github.com/rezmoss
https://github.com/manus-use
https://github.com/danieltk76
https://github.com/gigioneggiando
https://github.com/DshtAnger
https://github.com/manus-pi
https://github.com/silverwind
https://github.com/bircni
.