Executive brief
Gitea, a popular self-hosted Git service, contains a flaw in how it handles 'Remember-Me' login sessions. If an attacker steals a user's login token, they can maintain permanent access to the victim's account even after the theft is detected by the system. This allows an attacker to bypass security controls and persistently access private code repositories and user data.
Technical details
Gitea implements a split-token (ID:Hash) design for 'Remember-Me' cookies. When a token is used, the hash is rotated while the ID remains constant. If an attacker uses a stolen token, they receive a new rotated hash. When the legitimate user subsequently attempts to use their now-outdated token, Gitea's CheckAuthToken function correctly identifies a hash mismatch but only returns an error (ErrAuthTokenInvalidHash) without deleting the compromised token from the database. This failure to invalidate all sessions associated with the compromised ID allows the attacker's active session to persist indefinitely. The issue is fixed in version 1.27.0.
Affected products
- Gitea Gitea < 1.27.0
Timeline
- 2026-07-13: disclosed: Initial report to Gitea
- 2026-07-21: advisory: GitHub Advisory published
- 2026-07-21: patched: Fix released in version 1.27.0