Gitea API Vulnerability Exposes User Sessions via Improper File Handling
CVE-2026-96594

Currently unrated

Key Information:

Vendor

Gitea

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-96594?

A vulnerability in Gitea's API endpoint allows an attacker to expose user sessions by returning files without appropriate content type and disposition headers. As a result, browsers can render files inappropriately, enabling JavaScript execution within the context of a user's session. Users with push access to a repository could exploit this flaw, jeopardizing the security of those who interact with the media URL. Prompt awareness and remediation are crucial to mitigate potential risks.

Affected Version(s)

Gitea 0 <= 28.0.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

https://github.com/KadirArslan
https://github.com/cruzzer
https://github.com/silverwind
https://github.com/bircni
.