OAuth Token Introspection Vulnerability in Gitea
CVE-2026-58425
Currently unrated
What is CVE-2026-58425?
A significant security issue has been identified in Gitea related to OAuth token introspection. This vulnerability allows unauthorized retrieval of metadata for tokens that were issued to different clients, breaching RFC 7662 section 4 standards. Consequently, affected users may inadvertently expose sensitive information to unauthorized parties, leading to potential exploitation. It is essential for users of Gitea to upgrade to version 1.27.0 or later to mitigate the risks associated with this vulnerability.
Affected Version(s)
Gitea Open Source Git Server 0 <= 1.26.4
