CVE-2026-55982

Published: Ago 13, 2026 Last Modified: Ago 13, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes

200

Exposure of Sensitive Information to an Unauthorized Actor

Draft
Common Consequences
Security Scopes Affected:
Confidentiality
Potential Impacts:
Read Application Data
Applicable Platforms
Technologies: Not Technology-Specific, Web Based, Mobile
View CWE Details
https://blog.gitea.com/gitea-1.27.0-is-released/
https://github.com/go-gitea/gitea/releases/tag/v1.27.0
https://github.com/go-gitea/gitea/security/advisories/GHSA-mg4f-x9v4-6h2p