Gitea security advisory (AV26-845)

Serial Number: AV26-845
Date: August 25, 2026

As of August 14, 2026, Gitea is affected by vulnerabilities in the following product:

  • Gitea
    • Prior to 1.27.1

On August 25, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-60004 to their Known Exploited Vulnerabilities (KEV) Database.

The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.

Date modified: