CVE-2026-105268: Gitea
Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.
The Gitea API routes for issue attachments (`/api/v1/repos/{owner}/{repo}/issues/{index}/assets/{attachment_id}`) also accepted attachments that belong to comments on the issue. Because the author of an issue may edit and delete the issue's attachments, a user who opened an issue could rename or delete attachments that other users had posted in comments on that issue. The contents of the attachments could not be changed.
Affected products
- Gitea Gitea: up to and including 28.0.0
Published 2026-10-06. Last modified 2026-10-07.