Skip to content

Gitea v1.27.3 for Cloud is released

Gitea v1.27.3 for Cloud is released
2 min read

We are happy to announce that Gitea v1.27.3 is now rolling out to Gitea Cloud!

Every Gitea Cloud instance will be upgraded to v1.27.3 automatically during its configured maintenance window — nothing is required on your side.

Security fixes and disclosed CVEs

Gitea Cloud v1.27.3 includes the security fixes from both Gitea v1.27.2 and v1.27.3.

Fixed in Gitea 1.27.2

  • CVE-2026-73804: A write:user token could add an SSH key and bypass API token scope enforcement.
  • CVE-2026-73539: Markup renderer command argument injection could lead to remote code execution.
  • CVE-2026-73800: pull_request_target workflows resolved local reusable workflows unsafely.
  • CVE-2026-73278: OAuth2 and OpenID Connect sign-in could bypass WebAuthn-only second-factor authentication.
  • CVE-2026-73535: OpenID Connect linking did not enforce second-factor authentication.
  • CVE-2026-60008: Jupyter notebook renderer did not safely handle the notebook language metadata.
  • CVE-2026-73814: A repository collaborator with Admin access could escalate to Owner permissions and transfer the repository.

Fixed in Gitea 1.27.3

  • CVE-2026-66877: Approval gate for fork pull request workflows could be bypassed.
  • CVE-2026-71184: Maintainer approval gate was skipped for review comment events.
  • CVE-2026-68957: Restricted users could search and read issues belonging to Limited-visibility users.
  • CVE-2026-60010: Repository admins could attach arbitrary organization teams to private repositories.
  • CVE-2026-70406: Compare and pull request creation endpoints lacked the head repository token check.
  • CVE-2026-63792: Reusable workflow cross-repository read did not check whether a run came from a fork pull request.
  • CVE-2026-66874: Fork-controlled workflow filters could read workflow definitions from the pull request head.
  • CVE-2026-68964: SSH and GPG keys of Limited-visibility users were exposed through the API.
  • CVE-2026-67577: Limited-visibility user activity was exposed through API routes.
  • CVE-2026-66849: Restricted users could access packages owned by Limited-visibility users.
  • CVE-2026-73135: Some repository-search and listing endpoints exposed repositories owned by hidden users.
  • CVE-2026-78433: Legacy attachments skipped the cross-repository check.
  • CVE-2026-70407: Organization listing did not enforce the read:organization token scope.
  • CVE-2026-73126: Actions workflow badge endpoint did not enforce token scopes.
  • CVE-2026-70400: Migration API allowed creating private repositories with a public-only token.
  • CVE-2026-70396: Organization repository creation did not enforce the required token scope.
  • CVE-2026-63021: Swift package upload could amplify memory usage.
  • CVE-2026-62925: Alpine package upload could amplify memory usage.
  • CVE-2026-73273: Maven checksum upload could read without an upper bound.
  • CVE-2026-60021: GitLab migration probe used a timeout-less HTTP client.
  • CVE-2026-60018: OneDev migration read the remote response body without bound.
  • CVE-2026-73130: Repository gitignores field had no size limit.
  • CVE-2026-70402: Server-side Git hook directories and scripts were created with mode 0777.
  • CVE-2026-66853: Restricted users could enumerate Limited-visibility organizations.
  • CVE-2026-71301: Wiki-only members could resolve and read pull request references.
  • CVE-2026-73504: Actions artifact download endpoint leaked artifact existence.

Release notes

For the complete release notes, please refer to the links below: