Gitea's OAuth2 token endpoint verified the signature and grant of a token submitted with the `refresh_token` grant type, but not that the token was a refresh token. An unexpired access token for the same OAuth2 application and grant could be exchanged for a new access token and refresh token. Whoever holds such an access token could keep access beyond the token's original lifetime.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 07 Oct 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gitea
Gitea gitea |
|
| Vendors & Products |
Gitea
Gitea gitea |
Tue, 06 Oct 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-640 |
Tue, 06 Oct 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Gitea's OAuth2 token endpoint verified the signature and grant of a token submitted with the `refresh_token` grant type, but not that the token was a refresh token. An unexpired access token for the same OAuth2 application and grant could be exchanged for a new access token and refresh token. Whoever holds such an access token could keep access beyond the token's original lifetime. | |
| Title | Gitea OAuth2 refresh token grant accepts access tokens | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Gitea
Published:
Updated: 2026-10-06T21:34:53.642Z
Reserved: 2026-10-04T22:02:04.874Z
Link: CVE-2026-101023
No data.
Status : Received
Published: 2026-10-06T22:16:59.737
Modified: 2026-10-06T22:16:59.737
Link: CVE-2026-101023
No data.
OpenCVE Enrichment
Updated: 2026-10-07T04:30:11Z
Weaknesses