LIVE · cybersecurity feed
Live wire
vendor1 exploited in the wild

Gitea

1 CVEs published in the last four months and 5 stories. Exploited flaws first.

Critical1
High0
Medium0
Exploited (KEV)1

Patch these first

CVECVSSSeverityProductSummaryPublished
CVE-2026-60004exploited9.8criticalgiteaGitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.10d ago

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-60004exploited9.8criticalgiteaGitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.10d ago

Filter the full tracker by Gitea

Our coverage of Gitea

CVE-2026-60004critical

Hackers now exploit critical Gitea flaw in code injection attacks

Attackers are actively exploiting a critical code injection vulnerability (CVE-2026-60004) in the self-hosted Gitea Git service. The flaw allows authenticated users with write access to execute arbitrary shell commands, and with default open registration, unauthenticated attackers can exploit it by creating an account. Gitea has released version 1.27.1 to address the issue, and CISA has ordered U.S. federal agencies to patch within three days due to active exploitation, with reports indicating cryptocurrency mining malware deployment.

CVE-2026-60004

CISA Warns of Exploited Gitea Vulnerability

CVE-2026-60004 is a remote code execution vulnerability patched by Gitea developers in late July with the release of version 1.27.1. The post CISA Warns of Exploited Gitea Vulnerability appeared first on SecurityWeek.

CVE-2026-20896critical

Critical Gitea Docker Bug Under Active Exploitation Exposes Repositories and Secrets

A critical vulnerability in Gitea's Docker images, identified as CVE-2026-20896, allows attackers to bypass authentication using a single HTTP header. This flaw, stemming from insecure default configurations that trust any IP address for reverse proxy authentication, enables unauthorized access to repositories and sensitive data. Researchers have observed active exploitation of this vulnerability shortly after its disclosure.

CVE-2026-20896critical

Critical Gitea Flaw Under Active Exploitation, Researchers Warn

A critical vulnerability in Gitea, tracked as CVE-2026-20896, is being actively exploited. The flaw lets attackers bypass authentication with a single HTTP header to access repositories and secrets.

CVE-2026-20896critical

Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure

Threat actors have been observed attempting to exploit a recently patched critical security flaw in Gitea Docker images, according to Sysdig. The vulnerability in question is CVE-2026-20896 (CVSS score: 9.8), a vulnerability that stems from