Gitea Vulnerability Exposed Over 30,000 Deployments

TL;DR. A critical access control vulnerability in Gitea's container registry exposed thousands of private deployments to unauthorized access. - The flaw allowed unauthenticated attackers to pull private container images containing sensitive data. - NoScope, an AI pentesting firm, discovered the four-year-old defect (CVE-2026-27771). - Approximately 31,750 Gitea instances were vulnerable, with 4,000 running on production systems. - Organizations must update to Gitea version 1.26.2 immediately to patch the security hole.

Sources

Back to QLANKR News