CVE-2026-101023: Gitea

Critical severity, CVSS 9.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Gitea's OAuth2 token endpoint verified the signature and grant of a token submitted with the `refresh_token` grant type, but not that the token was a refresh token. An unexpired access token for the same OAuth2 application and grant could be exchanged for a new access token and refresh token. Whoever holds such an access token could keep access beyond the token's original lifetime.

Affected products

  • Gitea Gitea: up to and including 28.0.0

Published 2026-10-06. Last modified 2026-10-07.