{"id":"CVE-2026-56750","aliases":["GHSA-rgv6-xp99-6mgj"],"title":"Gitea Remember-Me Token Theft Not Invalidating Attacker Session","summary":"Gitea Remember-Me Token Theft Not Invalidating Attacker Session","severity":"critical","cwe":["CWE-613"],"vendor":"gitea","product":"code.gitea.io/gitea","ecosystem":"go","affected":["code.gitea.io/gitea < 1.27.0"],"patched":["code.gitea.io/gitea 1.27.0"],"published":"2026-07-21","updated":"2026-07-21","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-rgv6-xp99-6mgj","references":[{"url":"https://github.com/go-gitea/gitea/security/advisories/GHSA-rgv6-xp99-6mgj"},{"url":"https://github.com/go-gitea/gitea/pull/38406"},{"url":"https://github.com/go-gitea/gitea/pull/38426"},{"url":"https://github.com/go-gitea/gitea/commit/de4b8277e9cb576f2315fb03b5ab6478b42a1d31"},{"url":"https://github.com/go-gitea/gitea/commit/f69e15afe7496cc62e96dab244629c69eb31a7bf"},{"url":"https://github.com/go-gitea/gitea/releases/tag/v1.27.0"},{"url":"https://github.com/advisories/GHSA-rgv6-xp99-6mgj"}],"tags":["ghsa","go"],"ingestedAt":"2026-07-21T20:54:27.269Z","epss":0.00342,"epssPercentile":0.27711,"slug":"CVE-2026-56750","body":"## Overview\n\nThe vulnerability is in the Remember-Me (gitea_incredible) token validation logic, specifically when handling a compromised token (hash mismatch).\n\nThe vulnerable function is this one:\n\nhttps://github.com/go-gitea/gitea/blob/689ace1ce28fd74244b8aa335d9928cdbf6b22f9/services/auth/auth_token.go#L33-L64\n\n### Affected Endpoint\nPOST `/user/login` (and any endpoint triggering `autoSignIn` via the Remember-Me cookie).\n\n### Description\nGitea implements Remember-Me cookies using a split token design (ID:Hash), [citing the Paragonie secure remember-me guide](https://github.com/go-gitea/gitea/blob/689ace1ce28fd74244b8aa335d9928cdbf6b22f9/services/auth/auth_token.go#L21). When a token is used, its Hash is rotated, but the ID remains the same.\n\nIf an attacker steals a user's Remember-Me token and uses it to authenticate, the attacker is issued a new rotated token (same ID, new Hash). When the legitimate user later attempts to use their original token, Gitea correctly detects a hash mismatch for the given ID.\n\nAccording to the referenced Paragonie specification, this indicates a compromised token, and ALL active remember-me sessions for that user MUST be invalidated. However, Gitea's `CheckAuthToken` function simply returns `ErrAuthTokenInvalidHash`. The calling code (`autoSignIn`) catches this error and deletes the victim's local cookie via `ctx.DeleteSiteCookie`, but fails to delete the compromised token from the database.\n\nAs a result, the attacker's active session is never invalidated, and the attacker maintains persistent, indefinite access to the victim's account, entirely defeating the purpose of the split-token security design.\n\n## Affected packages\n\n- `code.gitea.io/gitea < 1.27.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `code.gitea.io/gitea 1.27.0`","depth":"midnight","depthScore":52,"depthScoreParts":{"impact":52.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}