Private Gitea Images Were Publicly Pullable

Gitea's 'private' container registry did not actually keep images private. On affected versions, an internet user could fetch them without an account or password, so the access control many operators relied on was absent at the registry level. Researchers say CVE-2026-27771 affects all Gitea versions before 1.26.2 and likely reaches more than 30,000 deployments in 30+ countries. Forgejo also failed the test check, and the exposed base includes healthcare, manufacturing, retail, and telecom environments. The risk is not just the bug itself. If private images were copied out over the four-year window, they may already carry code, configs, or embedded secrets into attacker hands, and patching now does not erase that history.

Part of the PlainSec briefing for 2026-05-27

Sources