Skip to main content

Tag: gitea

9 articles

Rows of computer servers and networking equipment in a neutral server room with cables on the floor and a single…

Red Heron Exploits Gitea Flaw to Compromise 13 Organizations Worldwide

Meet Red Heron, a suspected Chinese-linked threat actor who's been exploiting a Gitea flaw to compromise 13 organizations worldwide. Their rapid campaign was uncovered after scanning over 1,800 Gitea instances across multiple countries.

Analyst 207
Gitea server setup in a data center with a single server prominently displayed on a rack.

Gitea Servers Exposed to Ongoing Code Execution Attacks

Thousands of Gitea servers remain vulnerable to code execution attacks, with 8393 Internet-exposed IPs still susceptible to CVE-2026-60004, a code injection bug that lets attackers execute arbitrary shell commands. This flaw can be easily exploited by anyone with write access to a repository, which is especially concerning since Gitea enables self-registration by default.

Analyst 207
Rows of computer servers and development workstations in a brightly-lit server room or software development team's workspace.

Gitea Flaw Exploited in Code Injection Attacks

A critical flaw in Gitea, tracked as CVE-2026-60004, is being actively exploited in code injection attacks, putting nearly 5,000 self-hosted Git service instances at risk. Attackers can inject malicious code by submitting patches via Gitea's diffpatch API endpoint, allowing them to execute arbitrary shell commands.

Analyst 207
Rows of computer servers and networking equipment in a brightly-lit server room, with one server slightly ajar, suggesting…

Gitea Flaw Exploited to Deploy Miner-Like Payload

Hackers are actively exploiting a critical flaw in Gitea to deploy malicious payloads, including miner-like attacks, by abusing the diffpatch endpoint to install and execute Git hooks. This vulnerability allows attackers with repository write access to inject code and run shell commands, prompting a warning from the US Cybersecurity and Infrastructure Security Agency (CISA).

Analyst 207
Rows of computer servers and storage devices in a data center, with one device prominently featured in the foreground.

Gitea Flaw Exposes Server Files to Unauthenticated Attackers

A critical vulnerability, CVE-2026-59774, left self-hosted Gitea servers open to attack, allowing unauthenticated hackers to access sensitive files. Immediate action is required for self-hosted administrators to upgrade to version 1.27.1 and prevent exploitation.

Analyst 207
Cluttered coding workspace with computer, papers, and manuals, hinting at a Git project.

Gitea Flaw Lets Writers Run Shell Commands via Git Hook

A newly discovered vulnerability in Gitea, rated 9.8 in severity, allows ordinary repository writers to execute shell commands as the Gitea service account by exploiting a remote code execution bug via a cleverly planted Git hook. This critical flaw, tracked as CVE-2026-60004, puts Gitea users at risk of a devastating attack.

Analyst 207
Brightly-lit server in a data center with a network operations setting.

Hackers exploit auth bypass in Gitea Docker image

Hackers are actively exploiting a critical flaw in the Gitea Docker image, using a single header to bypass authentication and gain access - and security teams are only just catching on. In fact, researchers detected the first real-world hit just 13 days after the vulnerability was disclosed.

Analyst 207
Security researcher examines laptop amidst servers with Gitea Docker setup.

Threat Actors Probe Gitea Docker Flaw Just 13 Days After Patch

Security researchers have spotted threat actors probing a critical Gitea Docker flaw just 13 days after it was patched, highlighting the urgent need for users to update their systems. This highly vulnerable flaw, scoring 9.8, allows attackers to exploit a default setting that trusts user headers from any source IP address.

Analyst 207
Blurred container image on a pallet with a laptop showing a container registry in the background.

Gitea Flaw Exposes Private Container Images to Unauthenticated Attacks

A newly disclosed vulnerability in Gitea, tracked as CVE-2026-27771, allows unauthenticated attackers to access private container images, potentially exposing tens of thousands of deployments worldwide. This flaw lets anyone on the internet pull private images without needing an account, password, or credentials.

Analyst 207