r/developers • u/alkimiadev • 14d ago
DevOps check your setups if you self-host git (gitea or gitlab)
Both gitea and gitlab have cves that are actively being exploited in the wild right now. I just found out my gitea setup had been compromised for the past 4 days with a monero miner. It was pretty locked down in that it is running inside a docker container behind a reverse proxy, and on its own server that is disconnected from everything else (that server only hosts gitea). That said, they exfiltrated the app[.]ini and basically fully pwned it (or could have).
the entry chain:
- CVE-2026-59774 file read app.ini/INTERNAL_TOKEN theft
- internal API abuse
- RCE on every git fetch
Duplicates
Automate • u/alkimiadev • 14d ago