Over 8,300 internet-exposed Gitea servers remain vulnerable to active code injection attacks Shadowserver counted 8,393 exposed instances still unpatched against CVE-2026-60004. The flaw lets an authenticated attacker execute shell commands via Gitea’s diffpatch API, and default self-registration can provide the required repository write access. Gitea fixed the issue in 1.27.1 in Gitea’s advisory .
https://github.com/go-gitea/gitea/security/advisories/GHSA-rcr6-4jqh-j84m