Gitea 1.27.1 security patch release for CVE-2026-60004
Security Patch Release
Summary
Hide ▲
Show ▼
Gitea's 1.27.1 security patch release closes CVE-2026-60004, a critical RCE affecting Gitea versions 1.17 through 1.27.0. The fix requires upgrading to 1.27.1, and Gitea Cloud instances were set to update automatically. The advisory also noted public proof-of-concept code for the flaw.
Related Happenings
VBulletin 6.2.2 security patch release for template-engine flaw
Security Patch Release
H score32
First: 27.07.2026 17:40
Last: 27.07.2026 17:40
Sources 1
About this happening:
vBulletin released security patches for 6.2.1, 6.2.0, and 6.1.6 and shipped 6.2.2 as the fixed build, closing a template-engine remote code execution flaw on s...
VBulletin 6.2.2 security patch release for template-engine flaw
Security Patch ReleaseAbout this happening: vBulletin released security patches for 6.2.1, 6.2.0, and 6.1.6 and shipped 6.2.2 as the fixed build, closing a template-engine remote code execution flaw on s...
NodeBB eight-flaw security patch release (4.14.2)
Security Patch Release
H score34
First: 24.07.2026 10:41
Last: 24.07.2026 10:41
Sources 1
About this happening:
NodeBB released 4.14.2 to close eight high-severity flaws that exposed admin access, private messages, private categories, and code-execution paths. The affect...
NodeBB eight-flaw security patch release (4.14.2)
Security Patch ReleaseAbout this happening: NodeBB released 4.14.2 to close eight high-severity flaws that exposed admin access, private messages, private categories, and code-execution paths. The affect...
Linux kernel stable maintainers security patch release for CVE-2026-53359
Security Patch Release
H score41
First: 06.07.2026 20:37
Last: 06.07.2026 20:37
Sources 1
About this happening:
The Linux kernel shipped stable fixes for CVE-2026-53359, closing a KVM use-after-free on x86 hosts with nested virtualization. The fix reached 7.1.3, 6.18.3...
Linux kernel stable maintainers security patch release for CVE-2026-53359
Security Patch ReleaseAbout this happening: The Linux kernel shipped stable fixes for CVE-2026-53359, closing a KVM use-after-free on x86 hosts with nested virtualization. The fix reached 7.1.3, 6.18.3...
Gitea Docker images security update (CVE-2026-20896)
Security Patch Release
H score51
First: 06.07.2026 19:28
Last: 06.07.2026 19:28
Sources 1
About this happening:
Gitea released version 1.26.3 to fix CVE-2026-20896, closing a critical authentication-bypass risk in Gitea Docker images. The update removed the default "*" wildc...
Gitea Docker images security update (CVE-2026-20896)
Security Patch ReleaseAbout this happening: Gitea released version 1.26.3 to fix CVE-2026-20896, closing a critical authentication-bypass risk in Gitea Docker images. The update removed the default "*" wildc...
Linux kernel security update for Copy Fail (CVE-2026-31431)
Security Patch Release
H score39
First: 30.04.2026 16:54
Last: 30.04.2026 16:54
Sources 1
About this happening:
Linux kernel maintainers have fixed CVE-2026-31431 and are rolling out updates to close a local privilege escalation flaw that lets an unprivileged attacker gain roo...
Linux kernel security update for Copy Fail (CVE-2026-31431)
Security Patch ReleaseAbout this happening: Linux kernel maintainers have fixed CVE-2026-31431 and are rolling out updates to close a local privilege escalation flaw that lets an unprivileged attacker gain roo...
Timeline
-
29.07.2026 10:47 1 articles · 2h ago
Gitea changes the shared temporary clone to non-bare
Mitigation Patch UpdateTo close CVE-2026-60004, Gitea changes the shared temporary clone from bare to non-bare after warning that Git commands using --index may operate on the working tree.
Show sources
- New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands — thehackernews.com — 29.07.2026 10:47
-
29.07.2026 10:47 2 articles · 2h ago
Gitea 1.27.1 ships with the CVE-2026-60004 fix
Mitigation Patch UpdateGitea 1.27.1 ships as the fixed release for CVE-2026-60004, covering Gitea versions 1.17 and later before 1.27.1 and prompting automatic upgrades for Gitea Cloud instances.
Show sources
- New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands — thehackernews.com — 29.07.2026 10:47
- New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands — thehackernews.com — 29.07.2026 10:47
-
29.07.2026 10:47 1 articles · 2h ago
Gitea publishes the July 28 advisory with public proof-of-concept code
Initial DisclosureGitea's July 28 advisory credits security researcher Shai Rod, who goes by NightRang3r, and includes public proof-of-concept code while not reporting exploitation in the wild.
Show sources
- New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands — thehackernews.com — 29.07.2026 10:47