目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2026-58425— OAuth 令牌元信息泄露漏洞

AI Predicted 6.5 Difficulty: Moderate

Possible ATT&CK Techniques 1AI

T1528 · Steal Application Access Token

Affected Version Matrix 1

ベンダープロダクトVersion Rangeステータス
GiteaGitea Open Source Git Server≤ 1.26.4affected
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-58425の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
ソース: CVE Program / CVE List V5
脆弱性説明
OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
ソース: CVE Program / CVE List V5
CVSS情報
N/A
ソース: CVE Program / CVE List V5
脆弱性タイプ
信息暴露
ソース: CVE Program / CVE List V5

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
GiteaGitea Open Source Git Server 0 ~ 1.26.4 -

II. CVE-2026-58425の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2026-58425のインテリジェンス情報

登录查看更多情报信息。

CVE-2026-58425 厂商安全公告 (1)

CVE-2026-58425 安全博客文章 (1)

CVE-2026-58425 厂商页面 (1)

Same Patch Batch · Gitea · 2026-08-13 · 47 CVEs total

CVE-2026-58443Public-only repository tokens can update private PR head branches
CVE-2026-58507Private Repository Existence Disclosure via go-get Meta Endpoint
CVE-2026-58511Webhook Authorization Header Returned in Plaintext via API
CVE-2026-24059Gitea runner registration-token GET endpoint performs a write under a read-only token scop
CVE-2026-24791Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes
CVE-2026-58433Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setti
CVE-2026-58508Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)
CVE-2026-55986Email Management API Bypasses ManageCredentials Feature Restrictions
CVE-2026-59765SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud M
CVE-2026-58444Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/
CVE-2026-58445Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API
CVE-2026-58442Repository migration SSRF via multi-answer DNS allow-list bypass
CVE-2026-58441SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL
CVE-2026-58440Webhooks created by a collaborator keep firing after their repo access is revoked → ongoin
CVE-2026-58439Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
CVE-2026-58438Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment
CVE-2026-58437Repository Visibility Manipulation via Git Push Options
CVE-2026-58436ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
CVE-2026-58435Gitea LFS Deploy-Key Privilege Escalation
CVE-2026-58434Private Repository Metadata Remains Accessible After Access Revocation

Showing 20 of 47 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2026-58425へのコメント

まだコメントはありません


コメントを残す