Gitea is a technology platform tracked across 6 threat clusters and 12 intelligence report mentions on ThreatCluster. First observed April 28, 2026; most recent activity July 8, 2026.
A critical command injection vulnerability, CVE-2026-42271, in LiteLLM, an open-source AI gateway, allows unauthenticated remote code execution (RCE) when chained with CVE-2026-48710, a Host header validation bypass in…
An anonymous researcher known as Bikini has released exploit code for over a dozen zero-day vulnerabilities affecting 15 popular open-source projects, including the Linux kernel and Libssh2. The exploits were disclosed…
CVE-2026-20896 is a critical authentication bypass vulnerability (CVSS 9.8) affecting Gitea Docker images up to version 1.26.2. Discovered on July 3, 2026, the flaw allows unauthenticated remote attackers to impersonate…
A critical vulnerability, CVE-2026-27771, in Gitea's container registry allowed unauthenticated users to access private container images for nearly four years. Discovered by Noscope in April 2026, the flaw affects over…
CVE-2026-58426, published on July 3, 2026, reveals a critical vulnerability in Gitea Actions Artifacts V4. This flaw allows attackers to exploit HMAC ambiguities in signed URLs, enabling unauthorized cross-repository…
A security researcher identified multiple vulnerabilities in Forgejo, a software platform used by Fedora, including SSRF, cryptographic issues, and authentication flaws. The researcher was able to chain these…