External risk intelligence

Gitea OAuth2 Token Refresh Vulnerability Allows Extended Access

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-101023

Gitea is commonly deployed as a self-hosted, internet-facing application for code hosting and collaboration. As an OAuth2 token endpoint, this component is intended to handle authentication requests from external services and integrations, making it a functional part of the service's public-facing API surface.

Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in Gitea's OAuth2 implementation could allow an attacker to reuse an existing access token to obtain new tokens, effectively extending access beyond its intended expiration. This could potentially grant unauthorized persistent access to systems that rely on Gitea for authentication.

  • Access tokens can be reused for extended access.
  • Critical to confirm if Gitea is used for authentication.
  • Verify Gitea usage to understand potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending a crafted request to the OAuth2 token endpoint. If the attacker possesses an unexpired access token for the same OAuth2 application, they can submit it with a `refresh_token` grant type. Although the system verifies the signature and grant, it fails to confirm if the token is actually a refresh token. This allows an attacker to effectively renew their access, gaining extended privileges beyond the original token's intended lifespan.

  • Publicly accessible token endpoint.
  • Submitting an access token as a refresh token.
  • Extended access beyond token lifetime.

Live Threat

Current exploitation, exposure, and threat context

An unexpired access token could be misused to obtain new, longer-lasting tokens, allowing unauthorized continued access to the OAuth2 application. This could occur when an attacker gains possession of a valid access token and uses it to refresh their session beyond its intended expiration. The primary risk involves the extended, unauthorized use of application resources.

  • Access to OAuth2 application resources.
  • Misused access token to obtain new tokens.
  • Continued unauthorized access to services.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Gitea's OAuth2 token endpoint impacts services that use this functionality for authentication and access control. Application owners and platform teams are likely responsible for addressing this, as they manage the Gitea instances and their integrations. The immediate priority is to identify all deployed Gitea instances, assess their exposure, and determine if they are handling sensitive data or critical business functions before planning remediation.

  • Application owners should own the issue.
  • Verify OAuth2 token endpoint exposure.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Gitea?

Gitea is a popular, lightweight open-source software platform used primarily for hosting Git repositories. It provides developers and teams with a centralized space for version control, code collaboration, and managing project workflows. Because it functions as a self-hosted environment, organizations often deploy it to maintain full control over their source code and integrate it with internal developer tools or external authentication systems.

What does CWE-287 mean for CVE-2026-101023?

CWE-287 refers to Improper Authentication. In this specific case, the Gitea OAuth2 token endpoint fails to verify if a provided credential is truly a refresh token. Because the system only checks the signature and grant type, an attacker can substitute a standard access token to trick the server into issuing new tokens, effectively bypassing the intended authentication expiration logic.

How can an attacker trigger this vulnerability?

An attacker triggers this by sending a specifically crafted request to the Gitea OAuth2 token endpoint. The process requires them to already possess a valid, unexpired access token for the targeted OAuth2 application. This bug is not triggered by standard, legitimate use of the API, but specifically through the misuse of an access token where a refresh token is expected.

Is my instance at risk according to Halo Surface Signal?

Halo Surface Signal identifies Gitea as a frequently internet-facing application that manages authentication for various services. If your Gitea instance is exposed to the internet to support external integrations or remote access, it faces a higher likelihood of being reachable by unauthorized parties who might attempt to interact with the OAuth2 endpoint.

What should I do first to address this Gitea issue?

Start by identifying all Gitea instances within your environment and confirming which ones utilize OAuth2 for authentication and access control. Once mapped, prioritize these instances based on their connectivity and the sensitivity of the data they manage. Review official project release documentation for the appropriate security update to resolve the token validation logic.

References