Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-58428

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 6.5

Описание

Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)

A flaw was found in Gitea. An authenticated remote attacker with repository write permission could bypass the attachment extension allowlist via the web release edit form. This vulnerability allows the attacker to rename existing release attachments to forbidden file extensions, potentially leading to the distribution of malicious files or stored Cross-Site Scripting (XSS) attacks.

Отчет

The vulnerability, a Moderate attachment allowlist bypass in Gitea, allows an authenticated attacker to upload files with forbidden extensions by manipulating the web release edit form. However, Red Hat products are not affected by this flaw as the vulnerable code from routers/web/repo/release.go is not present in shipped components.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Pipelinesopenshift-pipelines-clientNot affected
OpenShift Pipelinesopenshift-pipelines/pipelines-cli-tkn-rhel9Not affected
OpenShift Pipelinesopenshift-pipelines/pipelines-opc-rhel9Not affected
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-cli-rhel9Not affected
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-controller-rhel9Not affected
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-watcher-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-434
https://bugzilla.redhat.com/show_bug.cgi?id=2515498code.gitea.io/gitea: Gitea: Attachment allowlist bypass via web release edit form

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
20 дней назад

Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)

redos
20 дней назад

Уязвимость gitea

redos
20 дней назад

Уязвимость gitea

CVSS3: 6.5
github
около 1 месяца назад

Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)

6.5 Medium

CVSS3