Unrated severityNVD Advisory· Published Oct 6, 2026
CVE-2026-101023
CVE-2026-101023
Description
Gitea's OAuth2 token endpoint verified the signature and grant of a token submitted with the refresh_token grant type, but not that the token was a refresh token. An unexpired access token for the same OAuth2 application and grant could be exchanged for a new access token and refresh token. Whoever holds such an access token could keep access beyond the token's original lifetime.
Affected products
1Patches
Vulnerability mechanics
References
5News mentions
0No linked articles in our index yet.