9.1
CVE-2026-101023
- EPSS 0.35%
- Veröffentlicht 06.10.2026 21:34:53
- Zuletzt bearbeitet 07.10.2026 21:17:06
- Erkennungen
Gitea OAuth2 refresh token grant accepts access tokens
Gitea's OAuth2 token endpoint verified the signature and grant of a token submitted with the `refresh_token` grant type, but not that the token was a refresh token. An unexpired access token for the same OAuth2 application and grant could be exchanged for a new access token and refresh token. Whoever holds such an access token could keep access beyond the token's original lifetime.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerGitea
≫
Produkt
Gitea
Default Statusunaffected
Version <=
28.0.0
Version
0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.35% | 0.269 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 9.1 | 3.9 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
https://github.com/go-gitea/gitea/pull/39501
https://github.com/go-gitea/gitea/pull/39507
https://blog.gitea.com/release-of-28.1.0/
https://github.com/go-gitea/gitea/releases/tag/v28.1.0
https://github.com/go-gitea/gitea/security/advisories/GHSA-469m-x4mw-38r3