Gitea's SSH key lookup was case-insensitive - a crafted RSA key could match another user's key. https://intel.threadlinqs.com/threat/TL-2026-3046 #ThreatIntel #CVE_2026_103059 #CVE_2026_70357 #Gitea

Gitea's SSH key lookup was case-insensitive - a crafted RSA key could match another user's key. https://intel.threadlinqs.com/threat/TL-2026-3046 #ThreatIntel #CVE_2026_103059 #CVE_2026_70357 #Gitea
Gitea fixed 27 issues across versions 28.0.0 and 28.1.0.
The most serious could allow sign-in as another user, but onl…
Want your own lightweight Git server?
Learn how to install and configure Gitea on Debian 12. Host your Git repositories, manage code, and collaborate from your own server with this step-by-step guide.
CVE-2026-73802 - gitea
The Gitea Runner may copy the host's system settings into the containers that run your automated tasks, even when the privileged option is turned off. This could let a job see or affect…
Too many irrelevant or confusing CVEs? Use stackflag.com
CVE-2026-101023 - gitea
Gitea's login system can be tricked into treating a regular access token like a refresh token, allowing anyone who has that token to request fresh access and refresh tokens and stay logged in…
Too many irrelevant or confusing CVEs? Use stackflag.com
CVE-2026-95106 - gitea
Gitea can accept a repository that contains two files with the same name. When this happens, the web interface shows the first version while the build system and downloads use the second version,…
Too many irrelevant or confusing CVEs? Use stackflag.com
CVE-2026-94205 - gitea
In Gitea, when a maintainer triggers certain actions on a pull request from a fork, the system may start the workflow without requiring explicit approval, even though the code comes from the…
Too many irrelevant or confusing CVEs? Use stackflag.com
CVE-2026-73278 - gitea
When people sign in to Gitea using an external service like OAuth or OpenID Connect, the system can skip the required security key check if that is the only two‑factor method set up. An attacker…
Too many irrelevant or confusing CVEs? Use stackflag.com
CVE-2026-103059 - gitea
If Gitea's built‑in SSH server is turned on, it checks public keys in a way that ignores letter case. An attacker who creates a key that is the same as a legitimate user's key except for…
Too many irrelevant or confusing CVEs? Use stackflag.com
A Gitea security update fixes 27 flaws, including SSRF bug CVE-2026-101027 and SSH key flaw CVE-2026-103059. Upgrade to Gitea 28.1.0 now.
#Gitea #Git #DevSecOps #SSRF #CVE2026101027 #CVE2026103059 #SupplyChainSecurity #Vulnerability
Self-Host Weekly (2026-10-02)
A new #homeassistant marketplace, updates and launches, a spotlight on #Tagr, and more in this week's #selfhosted recap!
#selfhost #selfhosting #opensource #foss #homelab #newsletter #privacy #nextcloud #raspberrypi #gitea #nios #wsl #unraid
Gitea jumps from the 1.x series to version 28.0, bringing audit logging, bot accounts, admin impersonation, and new collaboration features.
linuxiac.com/gitea-28-0-d...
🚀 New #release · Gitea v28.0.0 - Breaking: Git network ops now use internal proxy, update egress settings. Details, install & alternatives → https://selfhost.directory/project/gitea#update-19138026 #homeserverlife #gitea #git #security #opensource
Red Heron nutzt kritische Gitea-Lücke für internationale Cyberangriffe
#Cyberangriff @acronis #Cybersecurity #Cybersicherheit #Gitea #Linux #LinuxRootkit #RedHeron #Schadsoftware
Hop, un p'tit repo tout chaud sur #GitHub et bien planqué/synchronisé sur #Gitea ! 🚀
C'est mon p'tit script pour mettre à jour les invités #Proxmox (#LXC et #VM) sans prise de tête.
👉 C'est par ici : github.com/anyblabla/pr...
Rookery 1.1.0 released. One Rookery now hosts several Gitea runners — a row each for status, uptime and current job, with Start/Stop per runner. Bundled runner moves to gitea-runner v3.3.0.
It seems like whenever I work on #forgejo, some hacky code from the #gitea days pops up. If you use forgejo, you should really be grateful to the new maintainers for being the competent developers that they are.
And all the linting and checking they have sometimes is a PITA, but for a good […]