gitea

Hackers now exploit critical Gitea flaw in code injection attacks
Attackers are actively exploiting a critical code injection vulnerability (CVE-2026-60004) in the self-hosted Gitea Git service. The flaw allows authenticated users with write access to execute arbitrary shell commands, and with default open registration, unauthenticated attackers can exploit it by creating an account. Gitea has released version 1.27.1 to address the issue, and CISA has ordered U.S. federal agencies to patch within three days due to active exploitation, with reports indicating cryptocurrency mining malware deployment.

Critical Gitea Docker Bug Under Active Exploitation Exposes Repositories and Secrets
A critical vulnerability in Gitea's Docker images, identified as CVE-2026-20896, allows attackers to bypass authentication using a single HTTP header. This flaw, stemming from insecure default configurations that trust any IP address for reverse proxy authentication, enables unauthorized access to repositories and sensitive data. Researchers have observed active exploitation of this vulnerability shortly after its disclosure.

Critical Gitea Flaw Under Active Exploitation, Researchers Warn
A critical vulnerability in Gitea, tracked as CVE-2026-20896, is being actively exploited. The flaw lets attackers bypass authentication with a single HTTP header to access repositories and secrets.