Gitea v1.27.3 for Cloud is released

We are happy to announce that Gitea v1.27.3 is now rolling out to Gitea Cloud!
Every Gitea Cloud instance will be upgraded to v1.27.3 automatically during its configured maintenance window — nothing is required on your side.
Security fixes and disclosed CVEs
Gitea Cloud v1.27.3 includes the security fixes from both Gitea v1.27.2 and v1.27.3.
Fixed in Gitea 1.27.2
- CVE-2026-73804: A
write:usertoken could add an SSH key and bypass API token scope enforcement. - CVE-2026-73539: Markup renderer command argument injection could lead to remote code execution.
- CVE-2026-73800:
pull_request_targetworkflows resolved local reusable workflows unsafely. - CVE-2026-73278: OAuth2 and OpenID Connect sign-in could bypass WebAuthn-only second-factor authentication.
- CVE-2026-73535: OpenID Connect linking did not enforce second-factor authentication.
- CVE-2026-60008: Jupyter notebook renderer did not safely handle the notebook language metadata.
- CVE-2026-73814: A repository collaborator with Admin access could escalate to Owner permissions and transfer the repository.
Fixed in Gitea 1.27.3
- CVE-2026-66877: Approval gate for fork pull request workflows could be bypassed.
- CVE-2026-71184: Maintainer approval gate was skipped for review comment events.
- CVE-2026-68957: Restricted users could search and read issues belonging to Limited-visibility users.
- CVE-2026-60010: Repository admins could attach arbitrary organization teams to private repositories.
- CVE-2026-70406: Compare and pull request creation endpoints lacked the head repository token check.
- CVE-2026-63792: Reusable workflow cross-repository read did not check whether a run came from a fork pull request.
- CVE-2026-66874: Fork-controlled workflow filters could read workflow definitions from the pull request head.
- CVE-2026-68964: SSH and GPG keys of Limited-visibility users were exposed through the API.
- CVE-2026-67577: Limited-visibility user activity was exposed through API routes.
- CVE-2026-66849: Restricted users could access packages owned by Limited-visibility users.
- CVE-2026-73135: Some repository-search and listing endpoints exposed repositories owned by hidden users.
- CVE-2026-78433: Legacy attachments skipped the cross-repository check.
- CVE-2026-70407: Organization listing did not enforce the
read:organizationtoken scope. - CVE-2026-73126: Actions workflow badge endpoint did not enforce token scopes.
- CVE-2026-70400: Migration API allowed creating private repositories with a public-only token.
- CVE-2026-70396: Organization repository creation did not enforce the required token scope.
- CVE-2026-63021: Swift package upload could amplify memory usage.
- CVE-2026-62925: Alpine package upload could amplify memory usage.
- CVE-2026-73273: Maven checksum upload could read without an upper bound.
- CVE-2026-60021: GitLab migration probe used a timeout-less HTTP client.
- CVE-2026-60018: OneDev migration read the remote response body without bound.
- CVE-2026-73130: Repository
gitignoresfield had no size limit. - CVE-2026-70402: Server-side Git hook directories and scripts were created with mode
0777. - CVE-2026-66853: Restricted users could enumerate Limited-visibility organizations.
- CVE-2026-71301: Wiki-only members could resolve and read pull request references.
- CVE-2026-73504: Actions artifact download endpoint leaked artifact existence.
Release notes
For the complete release notes, please refer to the links below: