Gitea API Vulnerability in Issue Attachments Management
CVE-2026-105268

Currently unrated

Key Information:

Vendor

Gitea

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-105268?

A vulnerability exists in Gitea where API routes for issue attachments inadvertently permit users to manipulate attachments associated with comments. This oversight allows users who create issues to rename or delete attachments from comments, while the original content of these attachments remains unchanged. This behavior could potentially lead to confusion or misinformation among users interacting with issues and their respective comments.

Affected Version(s)

Gitea 0 <= 28.0.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

https://github.com/N0K0
https://github.com/silverwind
https://github.com/bircni
.