CVE-2026-105268

CVE-2026-105268 published: The Gitea API routes for issue attachments (`/api/v1/repos/{owner}/{repo}/issues/{index}/assets/{attachment_id}`) also accepted attachments that belong to comments on the issue. Because the author of an issue may edit and delete the issue's attachments, a u...

View full NVD advisory → ← Back to CVE watch