Threats Tagged 'cve-2026-58425'
View all threats tagged with 'cve-2026-58425'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-58425'
Click on any threat for detailed analysis and mitigation recommendations
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) (CVE-2026-58425)CVE-2026-58425 0 Gitea versions prior to 1.27.0 contain a vulnerability in the OAuth token introspection endpoint where metadata of tokens issued to other clients can be disclosed. The introspection endpoint fails to verify that the client requesting token introspection matches the token's original audience, violating RFC 7662 section 4. This allows an authenticated client to obtain metadata about tokens issued to different clients. The issue arises from a missing check comparing the introspecting client's ID with the token's issuing client ID. A patch addressing this check exists in related handlers but has not been applied to the introspection endpoint in affected versions. Join the discussion | GCVE Database | 07/21/2026, 20:21:33 UTC Added: 07/22/2026, 00:11:39 UTC |
Showing 1 to 1 of 1 result