Authorization bypass through user-controlled key in Gitea - CVE-2026-78433
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the web attachment handler when handling attachment requests through a repository path other than the repository that owns the attachment. A remote attacker can request a private repository attachment through a public repository attachment path to disclose sensitive information.
Exploitation requires knowledge of a specific attachment UUID, and only attachments created before 16 January 2026 are affected.