#gitea
5 stories taggedgitea.

China-Linked Red Heron Turns Gitea Flaw Into a Seven-Country Break-In Spree
Acronis researchers say the group scanned nearly 1,400 self-hosted code servers and singled out 477 systems in Taiwan.

8,300 Gitea servers still exposed to a code injection bug attackers are already using
A flaw in Gitea's diffpatch endpoint lets low-privilege users run shell commands on the server. CISA gave federal agencies three days to patch. Most operators haven't.

CISA: Hackers Are Actively Exploiting a Patched Gitea Flaw That Lets Them Run Malicious Commands
A security hole in Gitea, a widely used code-hosting platform, is being exploited in the wild. A patch has existed since late July, but federal agencies have until August 28 to apply it.

Gitea Patches Critical Flaw That Lets Repo Users Run Shell Commands
CVE-2026-60004 carries a 9.8 CVSS score and is fixed in Gitea 1.27.1. Anyone running an older self-hosted instance should update now.

Hackers Race to Exploit Gitea Flaw That Lets Anyone Log In as Admin
A missing check in Gitea's Docker images let attackers claim any username by adding a single header. Sysdig says probing began within days of the patch.