Tag: gitea
9 articles

Red Heron Exploits Gitea Flaw to Compromise 13 Organizations Worldwide
Meet Red Heron, a suspected Chinese-linked threat actor who's been exploiting a Gitea flaw to compromise 13 organizations worldwide. Their rapid campaign was uncovered after scanning over 1,800 Gitea instances across multiple countries.

Gitea Servers Exposed to Ongoing Code Execution Attacks
Thousands of Gitea servers remain vulnerable to code execution attacks, with 8393 Internet-exposed IPs still susceptible to CVE-2026-60004, a code injection bug that lets attackers execute arbitrary shell commands. This flaw can be easily exploited by anyone with write access to a repository, which is especially concerning since Gitea enables self-registration by default.

Gitea Flaw Exploited in Code Injection Attacks
A critical flaw in Gitea, tracked as CVE-2026-60004, is being actively exploited in code injection attacks, putting nearly 5,000 self-hosted Git service instances at risk. Attackers can inject malicious code by submitting patches via Gitea's diffpatch API endpoint, allowing them to execute arbitrary shell commands.

Gitea Flaw Exploited to Deploy Miner-Like Payload
Hackers are actively exploiting a critical flaw in Gitea to deploy malicious payloads, including miner-like attacks, by abusing the diffpatch endpoint to install and execute Git hooks. This vulnerability allows attackers with repository write access to inject code and run shell commands, prompting a warning from the US Cybersecurity and Infrastructure Security Agency (CISA).

Gitea Flaw Exposes Server Files to Unauthenticated Attackers
A critical vulnerability, CVE-2026-59774, left self-hosted Gitea servers open to attack, allowing unauthenticated hackers to access sensitive files. Immediate action is required for self-hosted administrators to upgrade to version 1.27.1 and prevent exploitation.

Gitea Flaw Lets Writers Run Shell Commands via Git Hook
A newly discovered vulnerability in Gitea, rated 9.8 in severity, allows ordinary repository writers to execute shell commands as the Gitea service account by exploiting a remote code execution bug via a cleverly planted Git hook. This critical flaw, tracked as CVE-2026-60004, puts Gitea users at risk of a devastating attack.

Hackers exploit auth bypass in Gitea Docker image
Hackers are actively exploiting a critical flaw in the Gitea Docker image, using a single header to bypass authentication and gain access - and security teams are only just catching on. In fact, researchers detected the first real-world hit just 13 days after the vulnerability was disclosed.

Threat Actors Probe Gitea Docker Flaw Just 13 Days After Patch
Security researchers have spotted threat actors probing a critical Gitea Docker flaw just 13 days after it was patched, highlighting the urgent need for users to update their systems. This highly vulnerable flaw, scoring 9.8, allows attackers to exploit a default setting that trusts user headers from any source IP address.

Gitea Flaw Exposes Private Container Images to Unauthenticated Attacks
A newly disclosed vulnerability in Gitea, tracked as CVE-2026-27771, allows unauthenticated attackers to access private container images, potentially exposing tens of thousands of deployments worldwide. This flaw lets anyone on the internet pull private images without needing an account, password, or credentials.