Gitea Under Fire — Critical CVEs 2026
Critical
RCE with public PoC (CVE-2026-60004, CVSS 9.8), Docker auth bypass under active exploitation (CVE-2026-20896), and token bypass for private repos (CVE-2026-58443). Analysis of all vulnerabilities from version 1.25 and upgrade guide to 1.27.1.
August 17, 2026 · CVE-2026-60004 · CVE-2026-58443 · CVE-2026-20896 · Gitea · Self-Hosting · AI-assisted
DirtyFrag — Universal Linux LPE
Patched
Two chained kernel bugs (xfrm-ESP since 2017, RxRPC since 2023) enable deterministic root access on all major Linux distributions. CVE-2026-43284 / CVE-2026-43500. Fully patched across all major distributions.
May 8, 2026 · Updated: Aug 6, 2026 · CVE-2026-43284 · CVE-2026-43500 · esp4 · esp6 · rxrpc · LPE
CVE-2026-31431 — CopyFail
Patched
Local privilege escalation in the Linux kernel via AF_ALG socket + splice(): controlled 4-byte write into the page cache. Present since 2017, disclosed April 29, 2026.
April 30, 2026 · CVE-2026-31431 · AF_ALG · algif_aead · LPE