VDB

GO-2026-4364

GO-2026-4364 PUBLISHED

Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea

Affected Products

VendorProductVersions
code.gitea.iogitea0, 0

Timeline

  • Feb 2, 2026 CVE Published
  • Mar 3, 2026 CVE Updated
  • May 1, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›