gitea News Articles

Recent news articles refferecing the vendors vulnerabilities.

Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries

Red Heron exploited Gitea CVE-2026-60004 to steal repositories, collect credentials, persist, and move laterally across victim networks

1 week ago

Over 8,300 Gitea servers vulnerable to code execution attacks

Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, according to cybersecurity watchdog Shadowserver.

3 weeks ago

CISA Confirms Gitea CVE-2026-60004 Exploited: Cryptominer Hits 5,000 Exposed Dev Servers

Gitea CVE-2026-60004, a CVSS 9.8 code-injection flaw, is now on CISA’s Known Exploited Vulnerabilities list after attackers deployed cryptocurrency-mining malware on unpatched dev servers. Federal

4 weeks ago

CISA Warns of Gitea Code Injection Vulnerability Exploited in Attacks

CISA added Gitea flaw CVE-2026-60004 to its KEV catalog, confirming active exploitation of the self-hosted Git service.

4 weeks ago

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004) - IT Security News

2026-08-26 13:08 Attackers have begun exploiting CVE-2026-60004, a critical code injection vulnerability in the Gitea Git platform, CISA confirmed on Tuesday by adding the vulnerability to...

4 weeks ago

Hackers now exploit critical Gitea flaw in code injection attacks

Attackers are now exploiting a critical-severity vulnerability in the Gitea self-hosted Git service, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA).

4 weeks ago

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004) - Help Net Security

Attackers have begun exploiting CVE-2026-60004, a critical code injection vulnerability in the Gitea Git platform

4 weeks ago

Critical Gitea Vulnerability (CVE-2026-60004) Actively Exploited for Crypto Mining – Upgrade to 1.27.1 Now

A critical vulnerability (CVE-2026-60004, CVSS 9.8) in Gitea allows users with repository write access to exploit the diffpatch endpoint, install malicious Git hooks, and achieve full server compromise. The flaw is under active exploitation, primarily for cryptocurrency mining. Organizations should ...

4 weeks ago

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

CISA adds CVE-2026-60004 to KEV amid active Gitea RCE exploitation; a separate reported attack deployed a miner-like dropper.

4 weeks ago

CISA Warns of Exploited Gitea Vulnerability

Hackers are exploiting CVE-2026-60004, a critical remote code execution vulnerability affecting the Gitea development platform.

4 weeks ago

New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands

Gitea fixes CVE-2026-60004, a 9.8 RCE that lets repository writers turn malicious patches into Git hooks and run commands.

Gitea Docker Flaw Now Actively Probed: One Header Grants Admin Access to Source Code

Gitea Docker CVE-2026-20896 is under active scanning: Sysdig detected attackers probing the CVSS 9.8 authentication bypass 13 days after the advisory, using one HTTP header to claim admin access to

Hackers exploit critical auth bypass in Gitea Docker image

Hackers are actively exploiting a critical vulnerability in the official Docker image for the Gitea self-hosted Git service that allows attackers to impersonate any user, including administrators.

Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure

Ravie LakshmananJul 06, 2026Vulnerability / DevOps

Critical Gitea Flaw Under Active Exploitation, Researchers Warn

Threat actors are exploiting a vulnerability in Gitea’s reverse-proxy authentication mechanism to access internet-accessible instances by supplying only a valid username.

Gitea Docker Images Ship Critical Authentication Bypass by Default

Threat actors began probing CVE-2026-20896 in Gitea Docker images just 13 days after disclosure. The critical authentication bypass stems from a permissive default configuration that lets attackers impersonate users via a spoofed HTTP header. With thousands of instances exposed, organizations must u...

Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure

CVE-2026-20896 lets reachable Gitea Docker containers trust spoofed X-WEBAUTH-USER headers when reverse proxy auth is enabled.

Gitea Container Vulnerability Exposes Private Container Images to Attackers - IT Security News

A critical security vulnerability in Gitea’s built-in container registry exposes private container images to unauthenticated attackers, raising significant concerns for organizations that rely on self-hosted Git and CI/CD environments. The flaw, tracked as CVE-2026-27771, allows remote attackers to ...

Gitea Container Registry Vulnerability Could Lead to Private Image Exposure - IT Security News

A critical vulnerability, tracked as CVE-2026-27771, has been discovered in Gitea’s built-in container registry, allowing unauthenticated remote attackers to access private container images without credentials. This flaw poses a serious risk as it can expose sensitive application data, including sou...

Gitea Flaw Left 30,000 Deployments' Private Container Images Readable for 4 Years

Gitea vulnerability CVE-2026-27771 let anyone pull private container images from 30,000-plus self-hosted deployments with no credentials required. Noscope found the flaw affected healthcare,

Gitea Vulnerability Exposed 30,000 Deployments to Attacks

CVE-2026-27771, an access control vulnerability in Gitea, exposed over 30,000 deployments to unauthorized access.

Gitea Vulnerability Exposes Private Container Images without Authentication

Gitea flaw CVE-2026-27771 exposed private container images across 30,000 deployments, risking unauthorized access worldwide.

No more news articles to load.