Gbhackers Gitea Releases Urgent Security Updates for 27 Vulnerabilities
Article Content
- •Gitea patched 27 vulnerabilities in versions 28.0.0 and 28.1.0.
- •Critical flaws include SSH authentication bypass and SSRF vulnerabilities.
- •Administrators must upgrade immediately to mitigate risks.
Gitea has released versions 28.0.0 and 28.1.0 on October 6, 2026, addressing 27 vulnerabilities, including critical flaws like CVE-2026-94205 and CVE-2026-95106. These vulnerabilities allow attackers to bypass SSH authentication and exploit server-side request forgery (SSRF) weaknesses. The flaws impact repository access, automated workflows, and internal connections, posing significant risks to self-hosted Gitea instances. Administrators are urged to upgrade immediately to mitigate these issues, which could lead to unauthorized access and execution of untrusted code. The vulnerabilities were disclosed on October 6, 2026, with CVSS scores indicating critical and high severity levels. Gitea's updates include fixes for account impersonation and workflow execution without approval, enhancing security for users. The situation requires immediate attention from administrators to safeguard their systems.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-101027 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of Gitea are affected?
How urgent is the need to patch?
What specific vulnerabilities should we focus on?
Continue Reading
Tensorlake npm Package Compromised by Shai-Hulud Worm On October 8, 2026, the Tensorlake npm package version 0.5.144 was compromised, delivering a credential-stealing worm known as Shai-Hulud. The malware, which was published through a compromised maintainer account, executes a preinstall hook that runs an obfuscated loader to harvest credentials from local files and CI…
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…