DEV Community

endoflife-ai
endoflife-ai

Posted on Originally published at endoflife.ai

Gitea's First KEV Entry: CVE-2026-60004, a Two-Day Federal Deadline, and a Release Policy With Nowhere to Hide

CISA added CVE-2026-60004 — a CVSS 9.8 code-injection flaw in Gitea's diffpatch endpoint — to the KEV catalog on August 25 with an August 28 deadline. Gitea's own advisory puts the affected range at 1.17 through 1.27.0: four years of releases. And because Gitea has no LTS and no backports, the only supported destination is 1.27.1 or later.

The Gitea Support Map

Release line First release Supported until In CVE-2026-60004 range? Status
Gitea 1.27 July 13, 2026 Current line Below 1.27.1 only — fixed from 1.27.1 Supported
Gitea 1.26 April 18, 2026 July 13, 2026 Yes — no patch coming to this line EOL
Gitea 1.25 October 29, 2025 April 18, 2026 Yes — no patch coming to this line EOL
Gitea 1.24 June 10, 2025 October 29, 2025 Yes — no patch coming to this line EOL
Gitea 1.23 January 9, 2025 June 10, 2025 Yes — no patch coming to this line EOL
Gitea 1.22 May 27, 2024 January 9, 2025 Yes — no patch coming to this line EOL
Gitea 1.17 – 1.21 July 30, 2022 onward Each line ended at its successor's release Yes — no patch coming to these lines EOL

What's covered

  • Key Dates at a Glance
  • What Gitea's Advisory Actually Says
  • The Gitea Support Map
  • No LTS Means the Ladder Has One Rung
  • What To Do, In Order
  • Related Reading

Full guide with every version, risk scores, and live updates: https://endoflife.ai/article-gitea-cve-2026-60004

Top comments (0)