UNKNOWN Go
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev
GO-2026-6035 · CVE-2026-57886 · GHSA-6c6r-5xr4-cr5m
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev
References
- ADVISORY https://github.com/go-gitea/gitea/security/advisories/GHSA-6c6r-5xr4-cr5m
- WEB https://github.com/go-gitea/gitea/commit/de4b8277e9cb576f2315fb03b5ab6478b42a1d31
- WEB https://github.com/go-gitea/gitea/commit/f69e15afe7496cc62e96dab244629c69eb31a7bf
- WEB https://github.com/go-gitea/gitea/pull/38406
- WEB https://github.com/go-gitea/gitea/pull/38426
- WEB https://github.com/go-gitea/gitea/releases/tag/v1.27.0
Ready to move
Start Securing
Free, no credit card | First findings in minutes