Post #3649834
2026-05-28 14:24 UTC
A security vulnerability labelled CVE-2026-27771 affecting Forgejo and Gitea is being widely reported recently.
Packages in Forgejo are visible to unauthenticated users if they are published under a public owner, as designed. It is not a security vulnerability, but a misunderstanding about the permissions and a good opportunity for users to review that they are not in a misconfigured state.
Please see the statement issued by the security team here for more details: https://codeberg.org/forgejo/website/issues/839#issuecomment-15980039
Replies (3)
-
@Ember@blobfox.coffee 2026-05-28 14:41
@forgejo@floss.social classic slop CVEs being a nuisance
-
@AliveDevil@tauri.earth 2026-05-28 15:05
@forgejo@floss.social Though adding (public/private) visibility settings to a package like Github has would be greatly appreciated.
-
@flesh@transfem.social 2026-05-28 16:29
@forgejo@floss.social "We found a vulnerability." 'Skill Issue.'