Skip to content
Gitea Releases Urgent Security Updates for 27 Vulnerabilities

Gitea Releases Urgent Security Updates for 27 Vulnerabilities

First seen 8 Oct 2026, 12:33 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 8, 2026 at 13:30 UTC
  • •Gitea patched 27 vulnerabilities in versions 28.0.0 and 28.1.0.
  • •Critical flaws include SSH authentication bypass and SSRF vulnerabilities.
  • •Administrators must upgrade immediately to mitigate risks.

Gitea has released versions 28.0.0 and 28.1.0 on October 6, 2026, addressing 27 vulnerabilities, including critical flaws like CVE-2026-94205 and CVE-2026-95106. These vulnerabilities allow attackers to bypass SSH authentication and exploit server-side request forgery (SSRF) weaknesses. The flaws impact repository access, automated workflows, and internal connections, posing significant risks to self-hosted Gitea instances. Administrators are urged to upgrade immediately to mitigate these issues, which could lead to unauthorized access and execution of untrusted code. The vulnerabilities were disclosed on October 6, 2026, with CVSS scores indicating critical and high severity levels. Gitea's updates include fixes for account impersonation and workflow execution without approval, enhancing security for users. The situation requires immediate attention from administrators to safeguard their systems.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-06
Gitea releases security updates
Versions 28.0.0 and 28.1.0 released to address 27 vulnerabilities, including critical flaws.
Gbhackers
2026-10-06
CVE-2026-94205 and CVE-2026-95106 published
Critical vulnerabilities disclosed with CVSS scores of 9.8 and 9.1, respectively.
Cybersecuritynews
2026-10-06
CVE-2026-101029 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-06
CVE-2026-96404 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-06
CVE-2026-101027 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-06
CVE-2026-70357 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-06
CVE-2026-104632 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-06
CVE-2026-103667 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (2)

Following this threat?

Track CVE-2026-101027 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of Gitea are affected?
Versions 28.0.0 and 28.1.0 are affected by the vulnerabilities.
How urgent is the need to patch?
The vulnerabilities are critical, and administrators are urged to upgrade immediately to prevent exploitation.
What specific vulnerabilities should we focus on?
Focus on CVE-2026-94205 and CVE-2026-95106, which are critical and allow for serious security breaches.