Vulnerabilities · 110 days ago

Private Gitea Images Were Publicly Pullable

Gitea's 'private' container registry did not actually keep images private. On affected versions, an internet user could fetch them without an account or password, so the access control many operators relied on was absent at the registry level.

Researchers say CVE-2026-27771 affects all Gitea versions before 1.26.2 and likely reaches more than 30,000 deployments in 30+ countries. Forgejo also failed the test check, and the exposed base includes healthcare, manufacturing, retail, and telecom environments.

The risk is not just the bug itself. If private images were copied out over the four-year window, they may already carry code, configs, or embedded secrets into attacker hands, and patching now does not erase that history.

CVE-2026-27771

NVD KEV

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-05-27

Editions

Related stories