Gitea's OAuth2 token endpoint verified the signature and grant of a token submitted with the `refresh_token` grant type, but not that the token was a refresh token. An unexpired access token for the same OAuth2 application and grant could be exchanged for a new access token and refresh token. Whoever holds such an access token could keep access beyond the token's original lifetime.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 06 Oct 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Gitea's OAuth2 token endpoint verified the signature and grant of a token submitted with the `refresh_token` grant type, but not that the token was a refresh token. An unexpired access token for the same OAuth2 application and grant could be exchanged for a new access token and refresh token. Whoever holds such an access token could keep access beyond the token's original lifetime. | |
| Title | Gitea OAuth2 refresh token grant accepts access tokens | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Gitea
Published:
Updated: 2026-10-06T21:34:53.642Z
Reserved: 2026-10-04T22:02:04.874Z
Link: CVE-2026-101023
No data.
Status : Received
Published: 2026-10-06T22:16:59.737
Modified: 2026-10-06T22:16:59.737
Link: CVE-2026-101023
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.