CVE-2026-58428

Published: Ago 13, 2026 Last Modified: Ago 13, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)

424

Improper Protection of Alternate Path

Draft
Common Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Bypass Protection Mechanism Gain Privileges Or Assume Identity
Applicable Platforms
Technologies: Not Technology-Specific, Web Based
View CWE Details
434

Unrestricted Upload of File with Dangerous Type

Draft
Common Consequences
Security Scopes Affected:
Integrity Confidentiality Availability
Potential Impacts:
Execute Unauthorized Code Or Commands
Applicable Platforms
Languages: ASP.NET, PHP, Not Language-Specific
Technologies: Web Server, AI/ML
View CWE Details
https://blog.gitea.com/gitea-1.27.0-is-released/
https://github.com/go-gitea/gitea/releases/tag/v1.27.0
https://github.com/go-gitea/gitea/security/advisories/GHSA-25gq-j9jx-43pg