CVE-2026-103667
Gitea's container registry served blob downloads with a `Content-Type` taken from the media type declared in pushed image manifests, without
CVSS
—
No CVSS
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Oct 6, 2026 · Last modified: Oct 6, 2026 · CWE-79
Not enough EPSS history yet.
Gitea's container registry served blob downloads with a `Content-Type` taken from the media type declared in pushed image manifests, without a `Content-Disposition` or restrictive content security policy. A user who can push container images can publish a blob containing HTML and JavaScript with a `text/html` media type. When a victim who is authenticated to the instance opens the blob URL in a browser, the script runs on the Gitea origin and can perform actions as the victim, such as creating API tokens.