Release Attachment Extension Allowlist Bypass in Gitea Software
CVE-2026-58428

Currently unrated

Key Information:

Vendor

Gitea

Vendor
CVE Published:
13 August 2026

What is CVE-2026-58428?

A vulnerability has been identified in Gitea that allows attackers to bypass the release attachment extension allowlist via the web release edit form. This issue may lead to unauthorized access to sensitive resources or data. Users are urged to ensure they are running the latest version of Gitea to mitigate potential risks associated with this vulnerability.

Affected Version(s)

Gitea Open Source Git Server 0 <= 1.26.4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

bl4cksku11
.