NoScope's AI agent discovered an important vulnerability (CVE-2026-27771) in Gitea, one of the most widely used self-hosted Git platforms.
The finding is now being discussed across @TheHackersNews and the broader security community.
If Gitea is part of the stack, patch it now.
More details: https://t.co/gZEbDQH8Bu
🚨 Gitea flaw exposes private container images without authentication.
https://t.co/MzzINUkRhN
CVE-2026-27771 affects all Gitea versions before 1.26.2 and likely impacts 30,000+ deployments worldwide. Attackers can pull private images without an account or password.
Update now or enable REQUIRE_SIGNIN_VIEW as a temporary workaround.
NoScope found CVE-2026-35482 an RCE in Alf, a self-hosted ticketing platform used for conferences, trade shows, and festivals worldwide
Full technical breakdown in comments 🧵
Load any Java class. Invoke the runtime. Execute commands on the underlying server.
Passed validation clean. Executed clean
CVE-2026-35482. Patched and disclosed.
CVE-2026-35482 https://t.co/JGpLTcuawb is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5-2606, a sandbox escape vulnerability … https://t.co/lRFPNNiPsA
🚨URGENT ADVISORY🚨Cybersecurity researchers have disclosed a critical vulnerability tracked as CVE-2026-27771, affecting Gitea.
Click here for more information👇
https://t.co/FLLzefLDjR
@cirtgovjm Glad that this vulnerability is getting enough attention. It needs to be fixed.
The vulnerability was found by our AI agent. More details - https://t.co/T8dsFruXF9
@cloudsa We're the team behind this. The vulnerability was discovered by our AI pentesting agent :)
More about the vulnerability: https://t.co/T8dsFruXF9
@Horizon3ai We're the team behind this. The vulnerability was discovered by our AI pentesting agent :)
More about the vulnerability: https://t.co/T8dsFruXF9
If you run Gitea: update to v1.26.2 now.
If you run Forgejo: treat yourself as affected until your maintainers confirm otherwise.
Full writeup: https://t.co/T8dsFruXF9
For 4 years, any person on the internet could pull private container images from 30,000+ Gitea deployments.
No account. No password. No credentials of any kind.
NoScope discovered it. CVE-2026-27771. Here's the full story. 🧵
Gitea assigned CVE-2026-27771 and officially credited NoScope in the v1.26.2 release.
At no point was any private image content accessed from any third-party host. All research was conducted in a controlled environment.