Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
News Gitea Vulnerability Exposes Private Container Images without Authentication
The Hacker News
2 months ago

Gitea Vulnerability Exposes Private Container Images without Authentication

By info@thehackernews.com (The Hacker News)

Cybersecurity researchers have disclosed a security flaw in Gitea, an open-source, self-hosted platform for version control, that allows unauthenticated remote attackers to pull private container images from Gitea deployments without requiring an account, password, or other credentials. The vulnerability, tracked as CVE-2026-27771 (CVSS score: 8.2), affects all versions of Gitea prior to 1.26.2

More from The Hacker News

Leaving Threaticon

This link opens an external site that isn't part of the platform.