Gitea Vulnerability Exposes Private Container Images without Authentication
EXPIRED
53.5
2026-05-28T07:00
Score-Aufschlüsselung
100
novelty
25
reach
35
concrete_impact
55
emotional_hook
70
source_quality
45
platform_fit
Zusammenfassung
Cybersecurity researchers have disclosed a security flaw in Gitea, an open-source, self-hosted platform for version control, that allows unauthenticated remote attackers to pull private container images from Gitea deployments without requiring an account, password, or other credentials. The vulnerability, tracked as CVE-2026-27771 (CVSS score: 8.2), affects all versions of Gitea prior to 1.26.2
Skripte (0)
e30c2caf…
Noch kein Skript generiert.
Score 53.5 — unter Schwellwert (65)