CVE-2026-101023
Gitea OAuth2 refresh token grant accepts access tokens
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Gitea's OAuth2 token endpoint verified the signature and grant of a token submitted with the `refresh_token` grant type, but not that the token was a refresh token. An unexpired access token for the same OAuth2 application and grant could be exchanged for a new access token and refresh token. Whoever holds such an access token could keep access beyond the token's original lifetime.
| Vendor | gitea |
| Product | gitea |
| Published | Oct 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for gitea gitea
Be the first to know when new unknown vulnerabilities affecting gitea gitea are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Gitea / Gitea
0 โค 28.0.0
References
github.com: https://github.com/go-gitea/gitea/security/advisories/GHSA-469m-x4mw-38r3 github.com: https://github.com/go-gitea/gitea/pull/39501 github.com: https://github.com/go-gitea/gitea/pull/39507 blog.gitea.com: https://blog.gitea.com/release-of-28.1.0/ github.com: https://github.com/go-gitea/gitea/releases/tag/v28.1.0
Credits
๐ https://github.com/rezmoss ๐ https://github.com/manus-use ๐ https://github.com/danieltk76 ๐ https://github.com/gigioneggiando ๐ https://github.com/DshtAnger ๐ https://github.com/manus-pi https://github.com/silverwind https://github.com/bircni