Improper Protection of Alternate Path in Gitea - CVE-2026-58428
Published: July 14, 2026
Vulnerability details
The vulnerability allows a remote user to bypass release attachment extension restrictions.
The vulnerability exists due to improper protection of alternate path in the EditReleasePost web release edit handler and release attachment rename logic when handling attachment rename form fields. A remote user can submit a specially crafted web release edit form to bypass release attachment extension restrictions.
Exploitation requires repository write permission and a non-empty release attachment allowlist to be configured.