Gitea 1.27.1 fixes CVE-2026-60004 rated 9.8
Gitea released version 1.27.1 to patch CVE-2026-60004, a code injection flaw in the diffpatch API. The CVSS 9.8 vulnerability needs no privileges or user interaction, was added to CISA's Known Exploited Vulnerabilities catalog, and had a federal remediation deadline of 28 August 2026.
- CVSS 9.8: network-reachable, no privileges, no user interaction
- Attacker can execute code as the Gitea service process
- Added to CISA KEV catalog; federal deadline 28 August 2026
- Exposure includes deploy keys, tokens and CI/CD secrets
Read next
Security