StackRadar

CVE-2026-60004

UnscoredKEV

Advisory

Published 10 Sept 2026In the index since 11 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.868
100th percentile
CISA KEV
Listed
since 25 Aug 2026
Charts affected
3
of 17,781 indexed, latest versions
Container images
3
deployed by those charts
Fix available
None
affected package

Gitea: Remote Code Execution via diffpatch Git Hook Installation in gitea.dev

Carried by container images the latest versions of 3 of 17,781 indexed charts deploy, on 3 images.

Affected packageAffected versionsFixed inImages
code.gitea.io/giteagolangv1.21.6, v1.22.3, v1.26.2+dirtyno fix listed3
OSV records
GO-2026-6433
Also known as
BIT-gitea-2026-60004, GHSA-rcr6-4jqh-j84m

Charts affected

3 by stars
ChartLatestAffected imagesRadar Score
ilumilumOfficialVerified publisher6.7.31 of 19See more

ilum ilum 6.7.3

1 of the 19 container images this version deploys carry CVE-2026-60004.

Container imageDigestPackageFixed in
gitea/gitea:1.22.376f516a1a8c2
code.gitea.io/gitea@v1.22.3
no fix listed

Open the chart page →

23,228
giteak8s-home-lab-repo2.6.01 of 1See more

gitea k8s-home-lab-repo 2.6.0

1 of the 1 container images this version deploys carry CVE-2026-60004.

Container imageDigestPackageFixed in
gitea/gitea:1.26.27d13848af126
code.gitea.io/gitea@v1.26.2+dirty
no fix listed

Open the chart page →

2,139
giteamyaVerified publisher23.12.51 of 1See more

gitea mya 23.12.5

1 of the 1 container images this version deploys carry CVE-2026-60004.

Container imageDigestPackageFixed in
gitea/gitea:1.21.6ac73e0da341f
code.gitea.io/gitea@v1.21.6
no fix listed

Open the chart page →

3,430

Container images carrying it

3 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
gitea/gitea:1.22.376f516a1a8c2
code.gitea.io/gitea@v1.22.3
no fix listed
1
gitea/gitea:1.26.27d13848af126
code.gitea.io/gitea@v1.26.2+dirty
no fix listed
1
gitea/gitea:1.21.6ac73e0da341f
code.gitea.io/gitea@v1.21.6
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.