We have shutdown our Gitea service for an emergency upgrade following the discovery of CVE-2026-60004 being exploitable on the service.
We did not receive notification from our usual source about this vulnerability, so we responded late. Sorry - we will do better next time. The good news is that:
- little to no sensitive data was on the server that could've been compromised (except an older prototype of Time Falcon from forever ago, go ahead and steal it lol)
- from the available data, we have no reason to believe we were actually attacked - Gitea's isolated user account has not exhibited any abnormal behavior.
Our server was, however, spammed by a CVE disclosure bot, which was what led us to this during a regular cleanup of dead accounts. So thanks to whoever did that.