CVE-2026-60004critical
Hackers now exploit critical Gitea flaw in code injection attacks
Attackers are actively exploiting a critical code injection vulnerability (CVE-2026-60004) in the self-hosted Gitea Git service. The flaw allows authenticated users with write access to execute arbitrary shell commands, and with default open registration, unauthenticated attackers can exploit it by creating an account. Gitea has released version 1.27.1 to address the issue, and CISA has ordered U.S. federal agencies to patch within three days due to active exploitation, with reports indicating cryptocurrency mining malware deployment.
CVE-2026-20896critical
Critical Gitea Docker Bug Under Active Exploitation Exposes Repositories and Secrets
A critical vulnerability in Gitea's Docker images, identified as CVE-2026-20896, allows attackers to bypass authentication using a single HTTP header. This flaw, stemming from insecure default configurations that trust any IP address for reverse proxy authentication, enables unauthorized access to repositories and sensitive data. Researchers have observed active exploitation of this vulnerability shortly after its disclosure.