logo

Gitea Vulnerability Exposes Private Container Images without Authentication

ID: 73e879ab-3b59-5f9e-8be2-a954f9d0d466

STIX ID: report--73e879ab-3b59-5f9e-8be2-a954f9d0d466

Feed Name: The Hacker News

Threat Score
65/100

Date Published: 2026-05-27

Date Updated: 2026-05-27

Author: [email protected] (The Hacker News)

...
...

Researchers disclosed CVE-2026-27771 in Gitea that permitted unauthenticated users to pull private container images from affected instances; the flaw affects versions prior to 1.26.2, likely impacts over 30,000 deployments across many countries and sectors, and Forgejo forks may also be impacted. Users are advised to upgrade to the fixed release or apply a temporary configuration workaround (service.REQUIRE_SIGNIN_VIEW=true) while noting the report contains an inconsistent version reference that should be validated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.