Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-101023: Gitea lets access token be used to get new tokens
CVE-2026-101023 · published 3 days ago
Summary
Gitea's login system can be tricked into treating a regular access token like a refresh token, allowing anyone who has that token to request fresh access and refresh tokens and stay logged in longer than intended. This can let an attacker keep access after the original token should have expired. Upgrade Gitea to the latest release that fixes the check and regenerate any existing tokens.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| gitea | gitea | <= 28.0.0 |
Original advisory text
Gitea OAuth2 refresh token grant accepts access tokens
Gitea's OAuth2 token endpoint verified the signature and grant of a token submitted with the `refresh_token` grant type, but not that the token was a refresh token. An unexpired access token for the same OAuth2 application and grant could be exchanged for a new access token and refresh token. Whoever holds such an access token could keep access beyond the token's original lifetime.
References
- https://blog.gitea.com/release-of-28.1.0/
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/101xxx/CVE-2026-1010... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-101023 Vendor Advisory
- https://github.com/go-gitea/gitea/security/advisories/GHSA-469m-x4mw-38r3
- https://github.com/go-gitea/gitea/pull/39501
- https://github.com/go-gitea/gitea/pull/39507
- https://github.com/go-gitea/gitea/releases/tag/v28.1.0
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.1
Critical
Type
CWE-287Improper Authentication
Timeline
Published6 Oct 2026
Updated9 Oct 2026
First seen6 Oct 2026
Sources
CVE-2026-101023 · NVD
CVE-2026-101023 · MITRE
CVE-2026-101023 · OSV
GHSA-469m-x4mw-38r3 · GHSA
Track software like this
Free during beta