[Bug 297194] update www/gitea to 1.27.1 to fix security issues
[email protected] Fri, 31 Jul 2026 11:49:20 +0000
| Newsgroups | gmane.os.freebsd.devel.ports.bugs |
|---|---|
| Message-ID | <[email protected]/bugzilla/> |
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=297194
Bug ID: 297194
Summary: update www/gitea to 1.27.1 to fix security issues
Product: Ports & Packages
Version: Latest
Hardware: Any
OS: Any
Status: New
Severity: Affects Many People
Priority: ---
Component: Individual Port(s)
Assignee: [email protected]
Reporter: [email protected]
CC: [email protected]
CC: [email protected]
Flags: maintainer-feedback?([email protected])
Created attachment 273344
--> https://bugs.freebsd.org/bugzilla/attachment.cgi?id=273344&action=edit
patch to update www/gitea port to 1.27.1
1.27.1 fixes these issues:
CVE-2026-59774: Unauthenticated arbitrary file read via the Org-mode #+INCLUDE
directive. Fixed by #38642 / #38645. Thanks to @xbow-security and,
independently, @NightRang3r for reporting the issue, and to @wxiaoguang and
@TheFox0x7 for the patch.
CVE-2026-60004: Remote code execution via the diffpatch API through Git hook
installation. Fixed by #38637 / #38638. Thanks to @NightRang3r for reporting
the issue, and to @wxiaoguang for the patch.
in addition to the issues fixed in 1.27.0, see
https://blog.gitea.com/release-of-1.27.0/
builds fine on 14.4, 15.0 and 15.1 (all amd64) here.
--
You are receiving this mail because:
You are the assignee for the bug.