FR
live
tag

#git

Gitea CVE-2026-59774 — Unauthenticated CVSS 9.8 File Read Escalates to RCE on Every Self-Hosted Instance

On August 2, 2026, Gitea shipped a critical fix for CVE-2026-59774, a path traversal that lets an unauthenticated attacker read any server file via Org-mode markup rendering on a public repository. Worse: by reading the INTERNAL_TOKEN from app.ini, the attacker can escalate to remote code execution. Every self-hosted Gitea administrator must patch and rotate secrets immediately.

Forgejo Runs Your Code Forge on 100 MB of RAM and Nobody Owns It

Forgejo shipped version 16.0 on July 16, 2026, three and a half years after the community fork from Gitea. A single 100 MB Go binary replaces both GitHub and GitLab on the cheapest VPS money can buy, with GitHub Actions-compatible CI/CD and governance locked under a non-profit foundation.

Type at least two characters.

navigate open esc dismiss