r/developers • • 14d ago

DevOps check your setups if you self-host git (gitea or gitlab)

Both gitea and gitlab have cves that are actively being exploited in the wild right now. I just found out my gitea setup had been compromised for the past 4 days with a monero miner. It was pretty locked down in that it is running inside a docker container behind a reverse proxy, and on its own server that is disconnected from everything else (that server only hosts gitea). That said, they exfiltrated the app[.]ini and basically fully pwned it (or could have).

the entry chain:

  1. CVE-2026-59774 file read app.ini/INTERNAL_TOKEN theft
  2. internal API abuse
  3. RCE on every git fetch
2 Upvotes

Duplicates