[Bug 297194] update www/gitea to 1.27.1 to fix security issues

[email protected] Fri, 31 Jul 2026 11:49:20 +0000
Newsgroups gmane.os.freebsd.devel.ports.bugs
Message-ID <[email protected]/bugzilla/>
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=297194

            Bug ID: 297194
           Summary: update www/gitea to 1.27.1 to fix security issues
           Product: Ports & Packages
           Version: Latest
          Hardware: Any
                OS: Any
            Status: New
          Severity: Affects Many People
          Priority: ---
         Component: Individual Port(s)
          Assignee: [email protected]
          Reporter: [email protected]
                CC: [email protected]
                CC: [email protected]
             Flags: maintainer-feedback?([email protected])

Created attachment 273344
  --> https://bugs.freebsd.org/bugzilla/attachment.cgi?id=273344&action=edit
patch to update www/gitea port to 1.27.1

1.27.1 fixes these issues:

CVE-2026-59774: Unauthenticated arbitrary file read via the Org-mode #+INCLUDE
directive. Fixed by #38642 / #38645. Thanks to @xbow-security and,
independently, @NightRang3r for reporting the issue, and to @wxiaoguang and
@TheFox0x7 for the patch.
CVE-2026-60004: Remote code execution via the diffpatch API through Git hook
installation. Fixed by #38637 / #38638. Thanks to @NightRang3r for reporting
the issue, and to @wxiaoguang for the patch.

in addition to the issues fixed in 1.27.0, see
https://blog.gitea.com/release-of-1.27.0/ 

builds fine on 14.4, 15.0 and 15.1 (all amd64) here.

-- 
You are receiving this mail because:
You are the assignee for the bug.