Skip to content
The Nexus
DossierENTITY

Gitea

Coverage of Gitea in the Nexus archive.

Earliest in view: Apr 30 · 19:22 UTCMost recent: Aug 26 · 11:07 UTC
Co-mentioned in this coverage
Recent coverage
  • SECURITYAug 26 · 11:07 UTCBLEEPING COMPUTER
    Hackers now exploit critical Gitea flaw in code injection attacks

    Attackers are currently exploiting a critical-severity vulnerability found in the Gitea self-hosted Git service. The flaw involves code injection attacks, according to information provided by the U.S. Cybersecurity and Infrastructure Security Agency (CISA).

  • SECURITYAug 26 · 06:27 UTCTHE HACKER NEWS
    Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned of active exploitation efforts targeting Gitea. The critical security flaw is identified as CVE-2026-60004, which allows for remote code execution. This vulnerability permits an attacker with ordinary write access to a repository to execute arbitrary shell commands.

  • SECURITYAug 5 · 11:04 UTCTHE HACKER NEWS
    Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup

    An unauthenticated attacker could exploit a critical flaw in Gitea versions 1.22.1 through 1.27.0 to read any file accessible by the service account. The vulnerability, tracked as CVE-2026-59774, requires only a public repository and crafted Org-mode markup. The issue was fixed in Gitea 1.27.1.

  • SECURITYMay 27 · 10:06 UTCTHE HACKER NEWS
    Gitea Vulnerability Exposes Private Container Images without Authentication

    A security flaw in Gitea, an open-source version control platform, allows unauthenticated attackers to access private container images. The vulnerability, CVE-2026-27771, affects all versions prior to 1.26.2 and was disclosed by cybersecurity researchers.

  • TECHNOLOGYMay 27 · 04:26 UTCHACKER NEWS
    Show HN: Posthorn, self-hosted mail without the mail server

    Posthorn is a self-hosted email gateway designed to simplify transactional email setup for self-hosted applications. It addresses challenges like VPS SMTP port restrictions and offers features such as HTTP POST support, anti-spam measures, and integration with providers like Postmark and Amazon SES. The open-source project is available under Apache 2.0.

  • TECHNOLOGYApr 30 · 19:22 UTCHACKER NEWS
    Follow-up to Carrot disclosure: Forgejo

    The article discusses a follow-up to a previous disclosure by Carrot, a company, regarding its use of Forgejo, an open-source project forked from Gitea. It highlights Forgejo's role as an alternative to other code hosting platforms.