Improper Protection of Alternate Path in Gitea - CVE-2026-58428

 

Improper Protection of Alternate Path in Gitea - CVE-2026-58428

Published: July 14, 2026


Vulnerability identifier: #VU137448
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-58428
CWE-ID: CWE-424
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass release attachment extension restrictions.

The vulnerability exists due to improper protection of alternate path in the EditReleasePost web release edit handler and release attachment rename logic when handling attachment rename form fields. A remote user can submit a specially crafted web release edit form to bypass release attachment extension restrictions.

Exploitation requires repository write permission and a non-empty release attachment allowlist to be configured.


Affected software

Gitea

How to mitigate CVE-2026-58428

Install security update from vendor's website.

Gitea - update to 1.27.0

External References

Related Security Bulletins