daily cyber × ai intelligence

index

tagged

[gitea]

8 editions · 8 items

August 27, 2026

  • Gitea CVE-2026-60004 (CVSS 9.8) is under active exploitation, per CISA. Ordinary repository write access is enough to execute arbitrary shell commands as the Gitea user; the fix landed in 1.27.1 in late July, and reported attacks are dropping a miner-like payload (BleepingComputer, The Hacker News). Self-hosted Git is a high-value pivot into build pipelines — treat this as CI/CD compromise, not a web bug. · Vulnerabilities & Exploits

in When the Sandbox Isn't a Boundary

July 8, 2026

  • A critical Gitea authentication bypass, CVE-2026-20896, is being probed in the wild. Official Gitea Docker images up to 1.26.2 with reverse-proxy auth enabled trusted any source IP as a proxy, letting an attacker who reaches the container's HTTP port spoof X-WEBAUTH-USER and impersonate a known/guessable user — accessing repos and secrets. Fixed in 1.26.3/1.26.4; a public PoC/checker exists, and Sysdig observed first in-the-wild probing 13 days post-disclosure. SecurityWeek · Vulnerabilities & Exploits

in Synacktiv Drops a Kerberos Reflection Bypass That Hands Attackers SYSTEM