Gitea Vulnerability Exposed Over 30,000 Deployments
TL;DR. A critical access control vulnerability in Gitea's container registry exposed thousands of private deployments to unauthorized access. - The flaw allowed unauthenticated attackers to pull private container images containing sensitive data. - NoScope, an AI pentesting firm, discovered the four-year-old defect (CVE-2026-27771). - Approximately 31,750 Gitea instances were vulnerable, with 4,000 running on production systems. - Organizations must update to Gitea version 1.26.2 immediately to patch the security hole.
- Threat actors could exploit CVE-2026-27771 to access private container images without authentication.
- The vulnerability, present for four years, impacted Gitea's built-in container registry and related forks.
- Sensitive information like source code and credentials were exposed in over 30,000 deployments.
- NoScope identified 4,000 exposed production systems, emphasizing the bug's significant impact.
- Users are urged to update to Gitea 1.26.2 to mitigate the risk of data breaches.
Sources
- Gitea Vulnerability Exposed 30,000 Deployments to Attacks — securityweek.com