Find notable cyber news and cases, enriched with sources, timelines, and signals.

Gitea security patch release for CVE-2026-59774

Security Patch Release
First reported
Last updated
Happening score
H score 65
1 unique sources, 1 articles

Summary

Hide ▲

Gitea 1.27.1 is a security patch release that closes CVE-2026-59774 and CVE-2026-60004, reducing exposure for self-hosted Gitea deployments. The update fixes a Critical file-read flaw affecting versions 1.22.1 through 1.27.0 and also patches a separate remote code execution bug. Cloud instances will be upgraded automatically during the release maintenance window, while self-hosted administrators are told to move to 1.27.1 immediately.

Related Happenings

Gitea 1.27.1 security patch release for CVE-2026-60004

Security Patch Release
H score46 First: 29.07.2026 10:47 Last: 29.07.2026 10:47 Sources 1

About this happening: Gitea's 1.27.1 security patch release closes CVE-2026-60004, a critical RCE affecting Gitea versions 1.17 through 1.27.0. The fix requires upgrading to 1.27.1,...

VBulletin 6.2.2 security patch release for template-engine flaw

Security Patch Release
H score32 First: 27.07.2026 17:40 Last: 27.07.2026 17:40 Sources 1

About this happening: vBulletin released security patches for 6.2.1, 6.2.0, and 6.1.6 and shipped 6.2.2 as the fixed build, closing a template-engine remote code execution flaw on s...

NodeBB eight-flaw security patch release (4.14.2)

Security Patch Release
H score34 First: 24.07.2026 10:41 Last: 24.07.2026 10:41 Sources 1

About this happening: NodeBB released 4.14.2 to close eight high-severity flaws that exposed admin access, private messages, private categories, and code-execution paths. The affect...

Ubuntu snap-confine patch release (CVE-2026-8933)

Security Patch Release
H score34 First: 22.07.2026 13:50 Last: 22.07.2026 13:50 Sources 1

About this happening: Canonical released snapd updates through the Ubuntu Security Team to fix CVE-2026-8933, a local privilege escalation in snap-confine that can let an unpriv...

Gitea Docker images security update (CVE-2026-20896)

Security Patch Release
H score51 First: 06.07.2026 19:28 Last: 06.07.2026 19:28 Sources 1

About this happening: Gitea released version 1.26.3 to fix CVE-2026-20896, closing a critical authentication-bypass risk in Gitea Docker images. The update removed the default "*" wildc...

Timeline

  1. 05.08.2026 14:04 1 articles · 1h ago

    Gitea discloses CVE-2026-59774 file-read flaw

    Initial Disclosure

    Gitea formally discloses CVE-2026-59774, a Critical file-read flaw in its self-hosted Git platform that lets an unauthenticated attacker read any file the service account can access through crafted Org-mode markup in a public repository. The advisory says versions 1.22.1 through 1.27.0 are affected and that Gitea 1.27.1 fixes the issue.

    Show sources
  2. 05.08.2026 14:04 2 articles · 1h ago

    Gitea 1.27.1 directs Cloud auto-upgrades and immediate self-hosted updates

    Mitigation Patch Update

    Gitea says Cloud instances will be upgraded automatically during the release maintenance window, and self-hosted administrators should move to Gitea 1.27.1 immediately. The same release also patches CVE-2026-60004 alongside CVE-2026-59774.

    Show sources