If you run Gitea and expose it to the Internet (why?), then you should update it now
If you run a self-hosted Gitea instance with the container registry enabled, your “private” images were not private. CVE-2026-27771, disclosed this week, reveals that any unauthenticated person on the internet could pull container images marked as private from Gitea deployments — no account, no password, no credentials required. The flaw went undetected for close to four years and likely affects more than 30,000 deployments worldwide. Update to Gitea 1.26.2 now.
Gitea CVE-2026-27771: Private Container Images Were Never Private | byteiota
Gitea Container Registry Flaw | Orca Security

