Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-58428— Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)

AI Predicted 7.8 Difficulty: Easy

Possible ATT&CK Techniques 1AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProductVersion RangeStatus
GiteaGitea Open Source Git Server≤ 1.26.4affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-58428

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
Source: CVE Program / CVE List V5
Vulnerability Description
Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
对候选路径的不恰当保护
Source: CVE Program / CVE List V5

Affected Products

VendorProductAffected VersionsCPESubscribe
GiteaGitea Open Source Git Server 0 ~ 1.26.4 -

II. Public POCs for CVE-2026-58428

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-58428

登录查看更多情报信息。

Vendor Advisories for CVE-2026-58428 (1)

Security Blog Posts for CVE-2026-58428 (1)

Vendor Pages for CVE-2026-58428 (1)

Same Patch Batch · Gitea · 2026-08-13 · 47 CVEs total

CVE-2026-58443Public-only repository tokens can update private PR head branches
CVE-2026-58507Private Repository Existence Disclosure via go-get Meta Endpoint
CVE-2026-58511Webhook Authorization Header Returned in Plaintext via API
CVE-2026-24059Gitea runner registration-token GET endpoint performs a write under a read-only token scop
CVE-2026-24791Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes
CVE-2026-58433Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setti
CVE-2026-58508Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)
CVE-2026-55986Email Management API Bypasses ManageCredentials Feature Restrictions
CVE-2026-59765SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud M
CVE-2026-58444Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/
CVE-2026-58445Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API
CVE-2026-58442Repository migration SSRF via multi-answer DNS allow-list bypass
CVE-2026-58441SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL
CVE-2026-58440Webhooks created by a collaborator keep firing after their repo access is revoked → ongoin
CVE-2026-58439Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
CVE-2026-58438Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment
CVE-2026-58437Repository Visibility Manipulation via Git Push Options
CVE-2026-58436ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
CVE-2026-58435Gitea LFS Deploy-Key Privilege Escalation
CVE-2026-58434Private Repository Metadata Remains Accessible After Access Revocation

Showing top 20 of 47 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2026-58428

No comments yet


Leave a comment