CVE-2026-103667

Summary

Gitea's container registry served blob downloads with a Content-Type taken from the media type declared in pushed image manifests, without a Content-Disposition or restrictive content security policy. A user who can push container images can publish a blob containing HTML and JavaScript with a text/html media type. When a victim who is authenticated to the instance opens the blob URL in a browser, the script runs on the Gitea origin and can perform actions as the victim, such as creating API tokens.

Affected Software

VendorProductVersion RangeStatus
GiteaGitea0 <= 1.27.3affected

Weaknesses

  • CWE-79: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

References