#Gitea
All CosmicBytez Labs articles tagged #Gitea, across news, security advisories, how-to guides, and projects.
- News
Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries
China-linked actor Red Heron weaponized Gitea RCE CVE-2026-60004 within days, breaching 13 orgs across six countries with a custom implant.
- Security
CVE-2026-89094: Forgejo Template Repository Flaw Enables Remote Code Execution
Forgejo before 16.0.4 mishandles template expansion, letting a malicious template repository achieve RCE on the Forgejo host. CVSS 9.9.
- News
Over 8,300 Gitea Servers Still Vulnerable to Active Code Execution Attacks
Shadowserver finds 8,300+ exposed Gitea instances unpatched against CVE-2026-60004, a critical RCE flaw already deploying cryptominers.
- News
Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload
CVE-2026-60004 lets any registered Gitea user hijack the server via a Git hook injection; CISA adds it to KEV after a reported miner deployment.
- News
Hackers Exploit Critical Auth Bypass in Official Gitea Docker Image
Attackers are actively exploiting a critical authentication bypass in the official Gitea Docker image, allowing unauthenticated users to impersonate any...
- Security
CVE-2026-20896: Gitea Docker Image Authentication Bypass
All official Gitea Docker images through v1.26.2 ship with a wildcard trusted proxy setting that lets any unauthenticated attacker impersonate any user...
- Security
CVE-2026-22874: Gitea SSRF Filter Bypass Exposes Cloud Credentials
Gitea versions through 1.26.2 use an incomplete IP filter that allows authenticated users to reach AWS Instance Metadata, Azure WireServer, and...
- News
Gitea Vulnerability Exposes Private Container Images without Authentication
A Gitea flaw lets unauthenticated remote attackers pull private container images from self-hosted deployments with no account or credentials required.