Release Attachment Extension Allowlist Bypass in Gitea Software
CVE-2026-58428
Currently unrated
What is CVE-2026-58428?
A vulnerability has been identified in Gitea that allows attackers to bypass the release attachment extension allowlist via the web release edit form. This issue may lead to unauthorized access to sensitive resources or data. Users are urged to ensure they are running the latest version of Gitea to mitigate potential risks associated with this vulnerability.
Affected Version(s)
Gitea Open Source Git Server 0 <= 1.26.4
