ctipilot.ch

Gitea container registry unauthenticated private-image pull (~30,000+ deployments, 4-year exposure window); Forgejo confirmed affected

cve · CVE-2026-27771

Coverage timeline
1
first 2026-05-28 → last 2026-05-28
Briefs
1
1 distinct
Sources cited
5
5 hosts
Sections touched
1
verification_notes
Co-occurring entities
0
no co-occurrence

Story timeline

  1. 2026-05-28CTI Daily Brief — 2026-05-28
    verification_notesFirst mention. Not in § 2 (did not clear inclusion gates — data exposure not RCE, no exploitation reported, no KEV/EUVD-critical). Logged for retrospective log review on instances < 1.26.2.

Where this entity is cited

  • verification_notes1

Source distribution

  • helpnetsecurity.com1 (20%)
  • msrc.microsoft.com1 (20%)
  • noscope.com1 (20%)
  • security-hub.ncsc.admin.ch1 (20%)
  • thehackernews.com1 (20%)

Items in briefs about Gitea container registry unauthenticated private-image pull (~30,000+ deployments, 4-year exposure window); Forgejo confirmed affected

No parsed item heading or body matches this entity yet. Items match by exact CVE id (for CVE entities), by lead-segment substring of the title in the item heading or body, or by a distinctive anchor token from the title appearing in the item heading. Coverage that lives inside a broader section (no per-item heading) is captured by the Story timeline above.