UNKNOWN NVD
CVE-2026-103667
Gitea's container registry served blob downloads with a `Content-Type` taken from the media type declared in pushed image manifests, without a `Content-Disposit
Gitea's container registry served blob downloads with a `Content-Type` taken from the media type declared in pushed image manifests, without a `Content-Disposition` or restrictive content security policy. A user who can push container images can publish a blob containing HTML and JavaScript with a `text/html` media type. When a victim who is authenticated to the instance opens the blob URL in a browser, the script runs on the Gitea origin and can perform actions as the victim, such as creating API tokens.
References
- https://blog.gitea.com/release-of-28.0.0/
- https://github.com/go-gitea/gitea/pull/39398
- https://github.com/go-gitea/gitea/releases/tag/v28.0.0
- https://github.com/go-gitea/gitea/security/advisories/GHSA-7cq7-4v93-8wjm
This unknown severity vulnerability was published on 2026-10-06 via NVD.
vulnfeed aggregates 9512 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.