Gitea’s private-image boundary was broken, so a registry meant to hide container images could serve them to anyone who knew the path. That turns a “private registry” into a source of code, embedded secrets, and infrastructure details, and patching only closes the door for future pulls.
The flaw is CVE-2026-27771 in Gitea’s built-in container registry. It was fixed in version 1.26.2. SecurityWeek says Forgejo and other Gitea-derived forks may share the same issue, and NoScope’s scan suggests more than 31,750 of 34,000-plus internet-facing Gitea instances were likely exposed, with thousands running production workloads.
The risk is not limited to source code. If secrets or cloud details were baked into image layers, anyone who pulled those private images could have kept a copy long after the registry was patched.