CISA added CVE-2026-60004 — a CVSS 9.8 code-injection flaw in Gitea's diffpatch endpoint — to the KEV catalog on August 25 with an August 28 deadline. Gitea's own advisory puts the affected range at 1.17 through 1.27.0: four years of releases. And because Gitea has no LTS and no backports, the only supported destination is 1.27.1 or later.
The Gitea Support Map
| Release line | First release | Supported until | In CVE-2026-60004 range? | Status |
|---|---|---|---|---|
| Gitea 1.27 | July 13, 2026 | Current line | Below 1.27.1 only — fixed from 1.27.1 | Supported |
| Gitea 1.26 | April 18, 2026 | July 13, 2026 | Yes — no patch coming to this line | EOL |
| Gitea 1.25 | October 29, 2025 | April 18, 2026 | Yes — no patch coming to this line | EOL |
| Gitea 1.24 | June 10, 2025 | October 29, 2025 | Yes — no patch coming to this line | EOL |
| Gitea 1.23 | January 9, 2025 | June 10, 2025 | Yes — no patch coming to this line | EOL |
| Gitea 1.22 | May 27, 2024 | January 9, 2025 | Yes — no patch coming to this line | EOL |
| Gitea 1.17 – 1.21 | July 30, 2022 onward | Each line ended at its successor's release | Yes — no patch coming to these lines | EOL |
What's covered
- Key Dates at a Glance
- What Gitea's Advisory Actually Says
- The Gitea Support Map
- No LTS Means the Ladder Has One Rung
- What To Do, In Order
- Related Reading
Full guide with every version, risk scores, and live updates: https://endoflife.ai/article-gitea-cve-2026-60004
Top comments (0)