Cross-Repository Issue in Gitea Exposes Private Attachment Content
CVE-2026-57886

Currently unrated

Key Information:

Vendor

Gitea

Vendor
CVE Published:
13 August 2026

What is CVE-2026-57886?

A cross-repository issue in Gitea allows for improper re-linking of comments and attachments, which may expose private attachment content. This vulnerability arises when user-generated content in one repository is able to reference or link to attachments stored in another. As a result, users could unintentionally gain access to sensitive information that should remain protected within private repositories. It is essential for users to update to the latest version to mitigate this risk and ensure the integrity of their private data.

Affected Version(s)

Gitea Open Source Git Server 0 <= 1.26.4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

zulloper
.