Feed/CVE-2026-28705
CVE-2026-28705MEDIUMCVSS 5.3

CVE-2026-28705

Published Jul 3, 2026·Updated Jul 7, 2026

NVD Description

Gitea versions before 1.25.5 use release tag names and asset names as filesystem path components when dumping release assets, allowing specially crafted names to affect dump output paths.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free