A AegiFlow
MEDIUMCVSS 4.3

CVE-2026-58425

Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)

Published
2026-07-21
Modified
2026-07-21
Aliases
GHSA-vxv2-8j6r-pcpg
Sources
github-advisory

Summary

## Live reproduction against Gitea 1.26.1 Setup: Gitea 1.26.1 docker stack with two users (`admin` and `victim`) and two OAuth applications owned by different users: ``` Client A: id=5dda747d-7fdd-4694-85ff-ce4f893ce51e owner=admin Client B: id=588f778f-4a41-4914-ae01-85d776c369db owner=victim ``` `admin` runs an OAuth flow against Client A and obtains an access token. `victim` (acting through Client B's credentials) calls the introspection endpoint with Client A's access token in the body: ``` $ curl -s -u "$B_ID:$B_SEC" -X POST http://localhost:3001/login/oauth/introspect \ --data-urlencode "token=$CLIENT_A_ACCESS_TOKEN" { "active": true, "username": "admin", "iss": "http://localhost:3001", "sub": "1", "aud": [ "5dda747d-7fdd-4694-85ff-ce4f893ce51e" ] } ``` Note the `aud` claim: the server explicitly states the token's audience is Client A, yet returns the full metadata to Client B. Per RFC 7662 section 4 ("The authorization server SHOULD also limit the information it discloses about each token to the resources that are authorized to receive it") the introspection result must not be disclosed to clients other than the token's audience. Full reproduction script attached as `poc.sh`. Full session log attached as `live_run.log`. ## Root cause `routers/web/auth/oauth2_provider.go:130-175` `IntrospectOAuth`: ```go func IntrospectOAuth(ctx *context.Context) { clientIDValid := false authHeader := ctx.Req.Header.Get("Authorization") if parsed, ok := httpauth.ParseAuthorizationHeader(authHeader); ok && parsed.BasicAuth != nil { clientID, clientSecret := parsed.BasicAuth.Username, parsed.BasicAuth.Password app, err := auth.GetOAuth2ApplicationByClientID(ctx, clientID) if err != nil && !auth.IsErrOauthClientIDInvalid(err) { log.Error("Error retrieving client_id: %v", err) ctx.HTTPError(http.StatusInternalServerError) return } clientIDValid = err == nil && app.ValidateClientSecret([]byte(clientSecret)) } if !clientIDValid { ctx.Resp.Header().Set("WWW-Authenticate", `Basic realm="Gitea OAuth2"`) ctx.PlainText(http.StatusUnauthorized, "no valid authorization") return } var response struct { Active bool `json:"active"` Scope string `json:"scope,omitempty"` Username string `json:"username,omitempty"` jwt.RegisteredClaims } form := web.GetForm(ctx).(*forms.IntrospectTokenForm) token, err := oauth2_provider.ParseToken(form.Token, oauth2_provider.DefaultSigningKey) if err == nil { grant, err := auth.GetOAuth2GrantByID(ctx, token.GrantID) if err == nil && grant != nil { app, err := auth.GetOAuth2ApplicationByID(ctx, grant.ApplicationID) // shadows the introspecting client's `app` if err == nil && app != nil { response.Active = true response.Scope = grant.Scope response.RegisteredClaims = oauth2_provider.NewJwtRegisteredClaimsFromUser(app.ClientID, grant.UserID, nil) } if user, err := user_model.GetUserByID(ctx, grant.UserID); err == nil { response.Username = user.Name } } } ctx.JSON(http.StatusOK, response) } ``` The handler: 1. Authenticates the introspecting client via HTTP Basic (`app.ValidateClientSecret`). The local variable `app` at this point references the introspecting client. 2. Loads the grant for `form.Token` via `auth.GetOAuth2GrantByID(ctx, token.GrantID)`. 3. **Reassigns** `app` to `auth.GetOAuth2ApplicationByID(ctx, grant.ApplicationID)` (line 162). After this point, `app` is the token's issuing client, not the introspecting client. 4. Populates `response` from the reassigned `app` and the grant. There is no comparison between the introspecting client's id and `grant.ApplicationID`. The endpoint will return metadata for any token whose JW

Affected packages

EcosystemPackageAffected versionsFixed versions
Gocode.gitea.io/gitea1.27.0

Remediation: Upgrade to 1.27.0 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.