CRITICAL
Hackers Exploit Critical Auth Bypass in Gitea Docker Image
Attackers are actively exploiting a critical vulnerability in the official Docker image for Gitea, the self-hosted Git service, that allows impersonation of any user, including administrators. Successful exploitation gives an attacker full administrative control over the affected Gitea instance. Organizations running the official Gitea Docker image should update to a patched version immediately and review instance logs for signs of unauthorized administrative activity.