Session Management Flaw in Gitea Affects User Authentication Process
CVE-2026-56750

Currently unrated

Key Information:

Vendor

Gitea

Vendor
CVE Published:
13 August 2026

What is CVE-2026-56750?

A session management vulnerability in Gitea allows an attacker to exploit the Remember-Me token theft, which does not invalidate the attacker's session upon token compromise. This flaw could allow unauthorized users to maintain access without needing to re-authenticate, potentially leading to further exploits. It is recommended to upgrade to the latest version to mitigate this risk. For more details, refer to the released security advisory and updates.

Affected Version(s)

Gitea Open Source Git Server 0 <= 1.26.4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

AdamKorcz
.