CVE-2026-28705

No CVSS score published

Path TraversalVendor advisory ref

Source data as of:

At a glance

Severity
No CVSS score published
CVSS
No CVSS score in the NVD record
EPSS
EPSS not provided by FIRST.org for this CVE
CISA KEV
No
Type
Path Traversal · NVD CWE
Published
2026-07-03 · Modified: 2026-07-03

CVSS / EPSS / KEV

EPSS EPSS not provided by FIRST.org for this CVE Source: FIRST.org
CISA KEV No Source: CISA

Source — CVSS: NVD · EPSS: FIRST.org · KEV: CISA. Data & Sources

Description

Gitea versions before 1.25.5 use release tag names and asset names as filesystem path components when dumping release assets, allowing specially crafted names to affect dump output paths.

Record details

CVE ID
CVE-2026-28705
CISA KEV
No
Weakness (CWE)
CWE-22
Affected configurations (CPE)
0
Published
2026-07-03
Modified
2026-07-03
Status
Received

References

Reference URLs as listed by NVD, grouped by a mechanical match on the link's host/pattern. Labels describe the link type only.