[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fdwEUXrdbUaa8qjXPocTiXr9wTUBkzdGFZ-uOZ98eM_g":3},{"article":4,"iocs":50},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":29,"category":30,"article_tags":34},"e330ae9f-514d-4ead-8fac-3e737fcc6ea2","Gitea Vulnerability Exposed 30,000 Deployments to Attacks","gitea-vulnerability-exposed-30-000-deployments-to-attacks-d13f76","The security flaw allowed attackers to pull private container images, exposing source code, credentials, and infrastructure. The post Gitea Vulnerability Exposed 30,000 Deployments to Attacks appeared first on SecurityWeek.","A four-year-old access control flaw in Gitea's container registry (CVE-2026-27771) allowed unauthenticated attackers to pull private container images, potentially exposing source code, credentials, and infrastructure details. Shodan analysis found over 34,000 internet-facing Gitea instances, with approximately 93% (31,750) likely vulnerable, including ~4,000 production systems. Gitea version 1.26.2 and Forgejo have patched the issue, and affected organizations are urged to update immediately.","Gitea vulnerability CVE-2026-27771 exposed 30,000+ deployments to unauthenticated container image pulls.","A vulnerability in open source, self-hosted Git service Gitea could have allowed unauthenticated attackers to pull private container images from over 30,000 deployments, AI pentesting firm NoScope warns. Tracked as CVE-2026-27771, the security flaw is described as an access control issue impacting Gitea’s built-in container registry. Forgejo, which shares the implementation, is also affected. Other Gitea-derived forks may be impacted as well. Due to the flaw, authentication requirements were not enforced on images marked as private, and the container registry still served them in response to standard, anonymous Docker\u002FOCI pull requests to the registry API. The security defect lurked in Gitea’s code for approximately four years before being patched in version 1.26.2, which was released last week. “Gitea’s container registry has allowed any person on the internet, with no account, no password, and no prior access, to pull what would be considered private container images at first glance from affected instances as if they were public,” NoScope says. Because container images may contain sensitive information such as source code, secrets, and production infrastructure details, the impact from the bug is considerable, the security firm warns.Advertisement. Scroll to continue reading. According to NoScope, a Shodan search uncovered over 34,000 internet-facing Gitea instances. Of these, approximately 93%, or 31,750, were likely vulnerable. Analysis of the potentially affected deployments revealed that roughly 4,000 were production systems running on major cloud or VPS platforms. Approximately 7,000 instances, NoScope says, were running on Gitea’s default port. “The data is unambiguous. These aren’t hobby machines. These are organisations that made a deliberate decision to self-host their development infrastructure, running it on production-grade compute, for real workloads,” the AI pentesting firm notes. Organizations are advised to update to Gitea version 1.26.2 immediately, or to change the configuration settings to require authentication for all content access. “Note that this setting is not suitable for instances that intentionally expose some containers publicly; operators in that situation should weigh the trade-off carefully,” NoScope says. Related: Vulnerability in Popular Conference Software Granted Attackers a 100% Talk Acceptance Rate Related: Open Source DockSec Uses AI to Cut Through Vulnerability Noise in Docker Images Related: Ghost CMS Vulnerability Exploited to Hack Over 700 Websites Related:‘Underminr’ Vulnerability Lets Attackers Hide Malicious Connections Behind Trusted Domains Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire GlassWorm Botnet DisruptedFBI: Hackers Sending Operatives in Person to Insert USB Drives and Steal DataCISA Urges Immediate Patching of Exploited LiteSpeed cPanel Plugin Zero-DayIranian APT Targets Aviation, Software Companies With Updated Tools185,000 Likely Impacted by 7-Eleven Data BreachHackers Exploited KnowledgeDeliver Zero-Day for Web Shell DeploymentAdmins of Bulletproof Hosting Service Used by Russian Hackers Arrested in Netherlands266,000 Affected by Data Breach at Radiology Associates of Richmond Latest News New Edamame Platform Aims to Catch AI Coding Agents Going Off the RailsRaising the Cybersecurity Stakes: Ante up for the Agentic EraGoogle Unveils AI Threat Defense Platform to Fight AI-Powered CyberattacksUK Cyberspying Chief Calls AI ‘an Unstoppable Force’ and Warns About RussiaVulnerability in Popular Conference Software Granted Attackers a 100% Talk Acceptance RateSecurityWeek to Host AI Risk Summit August 11-12 at the Ritz-Carlton, Half Moon BayRevEng.AI Raises $15 Million to Hunt for Flaws and Backdoors in Software BinariesRomanian Hacker Sentenced to Prison in US for Selling Access to State Network Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Threat Detection and Incident Response Summit On-Demand Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization. Register Webinar: Third-Party Risk in Practice June 4, 2026 Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice. Register People on the MoveJoe Chen has become Chief Technology Officer at Trellix.Usercentrics has named Pawan Hegde as COO and Elena Ignatova as CPTO.SecureAuth has named Mark van Oppen as Chief Revenue Officer.More People On The MoveExpert Insights Raising the Cybersecurity Stakes: Ante up for the Agentic Era CISOs are now facing machine-speed attacks and asking, “How do I agent?” The industry must provide remediation at scale. (Nadir Izrael) Caught Off Guard: Securing AI After It Hits Production As enterprises rush AI projects into production, security teams are increasingly being forced into reactive mode. (Joshua Goldfarb) Cyber Resilience is the New Business Continuity Plan The organizations best prepared to face disruption are those that align security, continuity and risk management around what the business cannot afford to lose. (Steve Durbin) Enhancing Data Center Security Without Sacrificing Performance For AI data centers, where the stakes are the highest and performance constraints are the tightest, security and performance are no longer a zero-sum game. (Nadir Izrael) Is the SOC Obsolete, and We Just Haven’t Admitted It Yet? Many AI-first enterprises have already embraced sovereign architectures for general AI initiatives; cybersecurity—and the SOC—should be next. (Danelle Au) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fgitea-vulnerability-exposed-30000-deployments-to-attacks\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2023\u002F01\u002FCybersecurity_News-SecurityWeek.jpg","2026-05-28T11:24:51+00:00","2026-05-28T12:00:25.285322+00:00",9,[18,21,23,26],{"name":19,"type":20},"Gitea","product",{"name":22,"type":20},"Forgejo",{"name":24,"type":25},"NoScope","vendor",{"name":27,"type":28},"Docker\u002FOCI","technology","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":29,"icon":31,"name":32,"slug":33},null,"Vulnerabilities","vulnerabilities",[35,40,45],{"category":36},{"id":37,"icon":31,"name":38,"slug":39},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":41},{"id":42,"icon":31,"name":43,"slug":44},"574f766a-fb3f-487c-8d2c-0720ae75471b","Zero-day","zero-day",{"category":46},{"id":47,"icon":31,"name":48,"slug":49},"ade75414-7914-4e23-a450-48b64546ee70","Open Source","open-source",[51],{"type":52,"value":53,"context":54},"cve","CVE-2026-27771","Access control vulnerability in Gitea container registry allowing unauthenticated image pulls"]