chiprook
← Security
SecurityOctober 2, 2026, 00:20

Gitea 1.27.1 fixes CVE-2026-60004 rated 9.8

Gitea released version 1.27.1 to patch CVE-2026-60004, a code injection flaw in the diffpatch API. The CVSS 9.8 vulnerability needs no privileges or user interaction, was added to CISA's Known Exploited Vulnerabilities catalog, and had a federal remediation deadline of 28 August 2026.

Gitea 1.27.1 fixes CVE-2026-60004 rated 9.8
#Gitea
Read next
Security

CVE-2026-9586: SQL injection in Sangoma Switchvox rated 9.8

Security

CVE-2026-81657 in IBM Guardium: deserialization flaw rated 9.8

Security

CVE-2026-77762 in Apache Tomcat: vendor rates Low, third parties 8.1

Security

CVE-2026-75682 in Adobe Connect: SQL injection rated 9.9 leads to code execution