Gitea security patch release for CVE-2026-59774
Security Patch Release
Summary
Hide ▲
Show ▼
Gitea 1.27.1 is a security patch release that closes CVE-2026-59774 and CVE-2026-60004, reducing exposure for self-hosted Gitea deployments. The update fixes a Critical file-read flaw affecting versions 1.22.1 through 1.27.0 and also patches a separate remote code execution bug. Cloud instances will be upgraded automatically during the release maintenance window, while self-hosted administrators are told to move to 1.27.1 immediately.
Related Happenings
Gitea 1.27.1 security patch release for CVE-2026-60004
Security Patch Release
H score46
First: 29.07.2026 10:47
Last: 29.07.2026 10:47
Sources 1
About this happening:
Gitea's 1.27.1 security patch release closes CVE-2026-60004, a critical RCE affecting Gitea versions 1.17 through 1.27.0. The fix requires upgrading to 1.27.1,...
Gitea 1.27.1 security patch release for CVE-2026-60004
Security Patch ReleaseAbout this happening: Gitea's 1.27.1 security patch release closes CVE-2026-60004, a critical RCE affecting Gitea versions 1.17 through 1.27.0. The fix requires upgrading to 1.27.1,...
VBulletin 6.2.2 security patch release for template-engine flaw
Security Patch Release
H score32
First: 27.07.2026 17:40
Last: 27.07.2026 17:40
Sources 1
About this happening:
vBulletin released security patches for 6.2.1, 6.2.0, and 6.1.6 and shipped 6.2.2 as the fixed build, closing a template-engine remote code execution flaw on s...
VBulletin 6.2.2 security patch release for template-engine flaw
Security Patch ReleaseAbout this happening: vBulletin released security patches for 6.2.1, 6.2.0, and 6.1.6 and shipped 6.2.2 as the fixed build, closing a template-engine remote code execution flaw on s...
NodeBB eight-flaw security patch release (4.14.2)
Security Patch Release
H score34
First: 24.07.2026 10:41
Last: 24.07.2026 10:41
Sources 1
About this happening:
NodeBB released 4.14.2 to close eight high-severity flaws that exposed admin access, private messages, private categories, and code-execution paths. The affect...
NodeBB eight-flaw security patch release (4.14.2)
Security Patch ReleaseAbout this happening: NodeBB released 4.14.2 to close eight high-severity flaws that exposed admin access, private messages, private categories, and code-execution paths. The affect...
Ubuntu snap-confine patch release (CVE-2026-8933)
Security Patch Release
H score34
First: 22.07.2026 13:50
Last: 22.07.2026 13:50
Sources 1
About this happening:
Canonical released snapd updates through the Ubuntu Security Team to fix CVE-2026-8933, a local privilege escalation in snap-confine that can let an unpriv...
Ubuntu snap-confine patch release (CVE-2026-8933)
Security Patch ReleaseAbout this happening: Canonical released snapd updates through the Ubuntu Security Team to fix CVE-2026-8933, a local privilege escalation in snap-confine that can let an unpriv...
Gitea Docker images security update (CVE-2026-20896)
Security Patch Release
H score51
First: 06.07.2026 19:28
Last: 06.07.2026 19:28
Sources 1
About this happening:
Gitea released version 1.26.3 to fix CVE-2026-20896, closing a critical authentication-bypass risk in Gitea Docker images. The update removed the default "*" wildc...
Gitea Docker images security update (CVE-2026-20896)
Security Patch ReleaseAbout this happening: Gitea released version 1.26.3 to fix CVE-2026-20896, closing a critical authentication-bypass risk in Gitea Docker images. The update removed the default "*" wildc...
Timeline
-
05.08.2026 14:04 1 articles · 1h ago
Gitea discloses CVE-2026-59774 file-read flaw
Initial DisclosureGitea formally discloses CVE-2026-59774, a Critical file-read flaw in its self-hosted Git platform that lets an unauthenticated attacker read any file the service account can access through crafted Org-mode markup in a public repository. The advisory says versions 1.22.1 through 1.27.0 are affected and that Gitea 1.27.1 fixes the issue.
Show sources
- Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup — thehackernews.com — 05.08.2026 14:04
-
05.08.2026 14:04 2 articles · 1h ago
Gitea 1.27.1 directs Cloud auto-upgrades and immediate self-hosted updates
Mitigation Patch UpdateGitea says Cloud instances will be upgraded automatically during the release maintenance window, and self-hosted administrators should move to Gitea 1.27.1 immediately. The same release also patches CVE-2026-60004 alongside CVE-2026-59774.
Show sources
- Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup — thehackernews.com — 05.08.2026 14:04
- Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup — thehackernews.com — 05.08.2026 14:04