Gitea v1.27.1 for Cloud is released

We are happy to announce that Gitea v1.27.1 is now rolling out to Gitea Cloud!
Every Gitea Cloud instance will be upgraded to v1.27.1 automatically during its configured maintenance window — nothing is required on your side.
Security fixes
Gitea v1.27.1 addresses the following advisories:
- CVE-2026-59774: Unauthenticated arbitrary file read via the Org-mode
#+INCLUDEdirective. - CVE-2026-60004: Remote code execution via the diffpatch API through Git hook installation.
The full Gitea 1.27.0 advisory list is published in the Gitea 1.27.0 release announcement.
Release notes
For the complete release notes, please refer to the links below: