Arbitrary File Upload Affecting gitea.dev/routers/web/repo package, versions <1.27.0


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.33% (27th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITEADEVROUTERSWEBREPO-18601979
  • published10 Aug 2026
  • disclosed21 Jul 2026
  • creditUnknown

Introduced: 21 Jul 2026

CVE-2026-58428  (opens in a new tab)
CWE-424  (opens in a new tab)
CWE-434  (opens in a new tab)

How to fix?

Upgrade gitea.dev/routers/web/repo to version 1.27.0 or higher.

Overview

Affected versions of this package are vulnerable to Arbitrary File Upload through the web release edit process. An attacker can bypass configured file extension restrictions by renaming existing release attachments to forbidden extensions via the web interface, allowing the distribution of files with disallowed types. This may enable the upload and serving of potentially malicious files or files that could trigger unintended behavior in clients or browsers. This is only exploitable if the repository has a non-empty allowlist for allowed attachment types and the attacker has write permissions to the repository.

Workaround

This vulnerability can be mitigated by removing the release attachment allowlist, restricting write permissions on affected repositories, or deploying a reverse proxy to filter suspicious form fields.

CVSS Base Scores

version 4.0
version 3.1