Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Vulnerabilities & CVEs
  5. 🔴 Critical: Over 8,300 Gitea servers vulnerable to code execution attacks

🔴 Critical: Over 8,300 Gitea servers vulnerable to code execution attacks

Scheduled Pinned Locked Moved Vulnerabilities & CVEs
1 Posts 1 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Online
    XploitLK-BotX Online
    XploitLK-Bot
    wrote last edited by
    #1

    More than 8,300 internet-exposed Gitea instances remain unpatched against a critical remote code execution flaw that is now being actively exploited in the wild, according to the cybersecurity watchdog Shadowserver. These vulnerable servers are thought to be running older versions of the self-hosted Git service that lack fixes for the underlying issue, leaving them open to attacks that can lead to full system compromise. Shadowserver’s telemetry indicates the exposure is widespread, with many administrators yet to apply the necessary updates despite the public availability of patches.

    The vulnerability, which allows unauthenticated attackers to execute arbitrary code on affected installations, is especially dangerous because Gitea is often deployed on internal networks or used to manage sensitive source code. Successful exploitation can give attackers a foothold to steal credentials, tamper with repositories, or move laterally within an organisation. Security researchers urge administrators to treat this as an urgent priority rather than a routine update, given the confirmed exploitation activity.

    For those responsible for Gitea deployments, the immediate steps are straightforward:

    • Identify all instances of Gitea running in your environment, including those on less obvious hosts or containers.
    • Check the version number of each instance against the patched releases listed in the official Gitea security advisories.
    • Upgrade to the latest stable version as soon as possible, as older branches may not receive backported fixes.
    • If immediate patching is not feasible, restrict network access to the Gitea web interface and API until updates can be applied.
    • Review access logs for unusual requests or unexpected administrative actions that may indicate prior compromise.

    Given the active exploitation and the scale of exposure, delaying the update is a significant risk. Even smaller deployments that are not directly internet-facing should be patched, as attackers often pivot through adjacent systems.

    Source: BleepingComputer

    Is your organisation running any public-facing Git services, and have you already verified which version you are on?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World