๐Ÿ” CVE Alert

CVE-2026-101023

UNKNOWN 0.0

Gitea OAuth2 refresh token grant accepts access tokens

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Gitea's OAuth2 token endpoint verified the signature and grant of a token submitted with the `refresh_token` grant type, but not that the token was a refresh token. An unexpired access token for the same OAuth2 application and grant could be exchanged for a new access token and refresh token. Whoever holds such an access token could keep access beyond the token's original lifetime.

Vendor gitea
Product gitea
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for gitea gitea

Be the first to know when new unknown vulnerabilities affecting gitea gitea are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Gitea / Gitea
0 โ‰ค 28.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/go-gitea/gitea/security/advisories/GHSA-469m-x4mw-38r3 github.com: https://github.com/go-gitea/gitea/pull/39501 github.com: https://github.com/go-gitea/gitea/pull/39507 blog.gitea.com: https://blog.gitea.com/release-of-28.1.0/ github.com: https://github.com/go-gitea/gitea/releases/tag/v28.1.0

Credits

๐Ÿ” https://github.com/rezmoss ๐Ÿ” https://github.com/manus-use ๐Ÿ” https://github.com/danieltk76 ๐Ÿ” https://github.com/gigioneggiando ๐Ÿ” https://github.com/DshtAnger ๐Ÿ” https://github.com/manus-pi https://github.com/silverwind https://github.com/bircni