www.securityweek.com 5/28/2026, 11:40:50 AM · external

Unauthenticated Gitea flaw leaks private images (CVE-2026-27771)

Unauthenticated Gitea flaw leaks private images (CVE-2026-27771)
CyberSIXT Evidence Panel
Primary Source blog.gitea.com
CISA KEV Not in KEV
Patch Patch Status Unknown

A vulnerability in the open-source Git service Gitea allows unauthenticated attackers to access private container images from over 30,000 affected instances. This flaw, tracked as CVE-2026-27771, is related to access control issues in Gitea's container registry, which did not enforce authentication for private images. The problem persisted for about four years before being fixed in version 1.26.2.

An estimated 93% of the 34,000 internet-facing Gitea instances are potentially vulnerable, impacting production systems running on major cloud platforms. Organizations are urged to update their deployments to prevent unauthorized access to sensitive information contained in these images.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline