discovered 03 Aug 2026
CVE-2026-27771
→ View on GitHubCVE-2026-27771 is a proof-of-concept tool that exploits an authentication bypass vulnerability in Gitea's OCI container registry, allowing unauthorized remote attackers to retrieve private container images from affected instances. Designed primarily for educational and authorized security research, it can scan for vulnerable Gitea setups and facilitate the pulling of container images without authentication. Notable features include scanning for instances, pulling all images or specific repositories, and the ability to operate with a personal access token when sign-in is required.