A security vulnerability in Gitea, an open-source, self-hosted version control platform, has been revealed by cybersecurity experts. This vulnerability enables unauthenticated remote attackers to extract private container images from Gitea installations without the need for an account, password, or other credentials.
Tracked as CVE-2026-27771 (CVSS score: N/A), the vulnerability affects all Gitea versions before 1.26.2, which fixes the problem.
Noscope reports that the security flaw went unnoticed for nearly four years and probably affects over 30,000 deployments in more than 30 countries. China, the United States, Germany, France, and the United Kingdom account for the great bulk of the exposures. Affected firms include internet service providers, retail infrastructure, aircraft manufacturers, and healthcare providers.
According to Noscope, the private designation on a container repository did not provide the protection that operators may have reasonably anticipated on impacted versions read more about Gitea Vulnerability Exposes Private Container Images without Authentication
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
