Junglewise Threat Intelligence

CVE-2026-58428: Gitea release attachment extension allowlist bypass in web edit form

CVE-2026-58428 · Severity: medium · CVSS 6.5 · Published 2026-07-21

Technologies: code.gitea.io/gitea (Go), Gitea, gitea.dev (Go). Vendors: Go, Gitea.

Executive brief

Gitea, a popular self-hosted Git service, contains a vulnerability where users with repository write access can bypass file extension restrictions on release attachments. By using the web-based release edit form, an attacker can rename an existing safe file (like a .zip) to a forbidden type (like a .exe or .html). This could be used to distribute malware masquerading as official project releases or to perform cross-site scripting (XSS) attacks against other users of the platform.

Technical details

A validation bypass exists in Gitea's web handler `EditReleasePost` within `routers/web/repo/release.go`. While the API endpoints were previously patched to enforce `Repository.Release.AllowedTypes` during attachment updates, the web-based edit path directly calls `repo_model.UpdateAttachmentByUUID` without invoking `upload.Verify`. An attacker with repository write access can submit a POST request to the release edit endpoint with a modified `attachment-edit-{uuid}` form field to rename an existing attachment to a forbidden extension (e.g., .exe, .html, .svg). This enables the distribution of restricted file types and potential stored XSS if the renamed files are rendered inline by the browser. The issue is fixed in version 1.27.0.

Affected products

  • Gitea Gitea < 1.27.0

Timeline

  • 2026-07-13: disclosed
  • 2026-07-21: advisory: GHSA-25gq-j9jx-43pg published

References

Related threats