Gitea
Coverage of Gitea in the Nexus archive.
- Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup
An unauthenticated attacker could exploit a critical flaw in Gitea versions 1.22.1 through 1.27.0 to read any file accessible by the service account. The vulnerability, tracked as CVE-2026-59774, requires only a public repository and crafted Org-mode markup. The issue was fixed in Gitea 1.27.1.
- Gitea Vulnerability Exposes Private Container Images without Authentication
A security flaw in Gitea, an open-source version control platform, allows unauthenticated attackers to access private container images. The vulnerability, CVE-2026-27771, affects all versions prior to 1.26.2 and was disclosed by cybersecurity researchers.
- Show HN: Posthorn, self-hosted mail without the mail server
Posthorn is a self-hosted email gateway designed to simplify transactional email setup for self-hosted applications. It addresses challenges like VPS SMTP port restrictions and offers features such as HTTP POST support, anti-spam measures, and integration with providers like Postmark and Amazon SES. The open-source project is available under Apache 2.0.
- Follow-up to Carrot disclosure: Forgejo
The article discusses a follow-up to a previous disclosure by Carrot, a company, regarding its use of Forgejo, an open-source project forked from Gitea. It highlights Forgejo's role as an alternative to other code hosting platforms.