security1 distinct publisher
A duplicate patch submission plants a live Git hook on unpatched Gitea servers
CVE-2026-60004 scores 9.8, but the reason it needs same-day attention is that Gitea ships with self-registration enabled, so the write access the exploit needs costs an attacker one signup. Only 1.27.1 fixes it.
Publishers:thehackernews.com
Reality
- Evidence74
- Adoption34
- Hype gap+6
- Incentives58