UNKNOWN Go
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev
GO-2026-6028 · CVE-2026-58428 · GHSA-25gq-j9jx-43pg
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev
References
- ADVISORY https://github.com/go-gitea/gitea/security/advisories/GHSA-25gq-j9jx-43pg
- WEB https://github.com/go-gitea/gitea/commit/de4b8277e9cb576f2315fb03b5ab6478b42a1d31
- WEB https://github.com/go-gitea/gitea/commit/f69e15afe7496cc62e96dab244629c69eb31a7bf
- WEB https://github.com/go-gitea/gitea/pull/38406
- WEB https://github.com/go-gitea/gitea/pull/38426
- WEB https://github.com/go-gitea/gitea/releases/tag/v1.27.0
Ready to move
Start Securing
Free, no credit card | First findings in minutes