If you run a self-hosted Gitea instance with the container registry enabled, your “private” images were not private. CVE-2026-27771, disclosed this week, reveals that any unauthenticated person on the internet could pull container images marked as private from Gitea deployments, no account, no password, no credentials required. The flaw went undetected for close to four years and likely affects more than 30,000 deployments worldwide https://byteiota.com/gitea-cve-2026-27771-private-container-images-were-never-private/ submitted by /u/Buildthehomelab [link] [comments]