OAuth Token Introspection Vulnerability in Gitea
CVE-2026-58425

Currently unrated

Key Information:

Vendor

Gitea

Vendor
CVE Published:
13 August 2026

What is CVE-2026-58425?

A significant security issue has been identified in Gitea related to OAuth token introspection. This vulnerability allows unauthorized retrieval of metadata for tokens that were issued to different clients, breaching RFC 7662 section 4 standards. Consequently, affected users may inadvertently expose sensitive information to unauthorized parties, leading to potential exploitation. It is essential for users of Gitea to upgrade to version 1.27.0 or later to mitigate the risks associated with this vulnerability.

Affected Version(s)

Gitea Open Source Git Server 0 <= 1.26.4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

bl4cksku11
.