Gitea Vulnerability Exposes Private Container Images without Authentication
A significant vulnerability (CVE-2026-27771) has been identified in Gitea, a popular open-source Git repository hosting platform. The flaw allows unauthorized access to private container images, exposing sensitive data without authentication. This issue has been present for nearly four years and affects a large number of deployments globally.
The vulnerability, discovered by Noscope, allows attackers to pull private container images from Gitea instances without requiring any credentials. This means anyone with internet access could potentially access confidential data stored within the platform. Noscope estimates that over 30,000 Gitea deployments across more than 30 countries are affected, with a disproportionate number located in China, the U.S., Germany, France, and the U.K. Organizations across various sectors, including healthcare, aerospace, retail, and internet services, are potentially at risk.
