[ANN] Check your setups if you self-host git (gitea or gitlab)
Both gitea and gitlab have cves that are actively being exploited in the wild right now. I just found out my gitea setup had been compromised for the past 4 days with a monero miner. It was pretty locked down in that it is running inside a docker container behind a reverse proxy, and on its own server that is disconnected from everything else (that server only hosts gitea). That said, they exfiltrated the app[.]ini and basically fully pwned it (or could have). the entry chain: CVE-2026-59774 file read app.ini/INTERNAL_TOKEN theft > internal API abuse > RCE on every git fetch
Link: https://github.com/go-gitea/gitea/security/advisories/GHSA-6v53-hr58-556r
Author: alkimiadev
Contact: alkimiadev (Reddit)
Note:
This is a free community message from alkimiadev.
Read the service announcement for more info.
Always DYOR and make use of reputable escrow services. I do not/can not verify anything. Report any suspicious messages.
