FR
live
tag

#self-hosted

Metabase Zero-Day CVSS 10.0 Grants Full Admin Access Without Authentication

On August 8, 2026, Metabase disclosed a maximum-severity SQL injection flaw (CVSS 10.0) that was already being exploited in the wild. The vulnerability lets unauthenticated attackers gain administrator privileges and drain every connected database. Self-hosted Metabase admins must patch, revoke sessions, and rotate all secrets immediately.

Gitea CVE-2026-59774 — Unauthenticated CVSS 9.8 File Read Escalates to RCE on Every Self-Hosted Instance

On August 2, 2026, Gitea shipped a critical fix for CVE-2026-59774, a path traversal that lets an unauthenticated attacker read any server file via Org-mode markup rendering on a public repository. Worse: by reading the INTERNAL_TOKEN from app.ini, the attacker can escalate to remote code execution. Every self-hosted Gitea administrator must patch and rotate secrets immediately.

Authentik Locks Every Self-Hosted Service Behind One Password

Authentik has become the default identity provider for self-hosters in 2026, surpassing both Authelia and Keycloak. One Docker Compose file, five minutes of configuration, and every service you run shares the same login, the same MFA, and the same user directory.

Forgejo Runs Your Code Forge on 100 MB of RAM and Nobody Owns It

Forgejo shipped version 16.0 on July 16, 2026, three and a half years after the community fork from Gitea. A single 100 MB Go binary replaces both GitHub and GitLab on the cheapest VPS money can buy, with GitHub Actions-compatible CI/CD and governance locked under a non-profit foundation.

Jellyfin Is the Netflix Alternative That Answers to No One

On April 29, 2025, Plex doubled its lifetime price to $249.99 and killed free remote streaming. One year later, Jellyfin has crossed 50,000 GitHub stars, 360 million Docker pulls, and 51% market share among self-hosters. If you own a server and a media collection, paying to stream it no longer makes sense.

Type at least two characters.

navigate open esc dismiss