FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

gitea -- Multiple vulnerabilities

Affected packages
gitea < 1.27.1

Details

VuXML ID f4af92f7-95ae-11f1-a6f7-b42e991fc52e
Discovery 2026-08-11
Entry 2026-08-11

Gitea reports

This release addresses the following security vulnerabilities. Please upgrade as soon as possible.

Unauthenticated arbitrary file read via the Org-mode #INCLUDE directive.

Remote code execution via the diffpatch API through Git hook installation.

References

CVE Name CVE-2026-59774
CVE Name CVE-2026-60004
URL https://github.com/go-gitea/gitea/security/advisories/GHSA-6v53-hr58-556r
URL https://github.com/go-gitea/gitea/security/advisories/GHSA-rcr6-4jqh-j84m