Gitea 1.27.3 security patches: 2026 Actions and API fixes explained
Gitea 1.27.3 shipped on 29 August with a large security batch. The official blog flags Actions trust, API token scopes, package visibility, and migration hangs. Forty-one pull requests. Upgrade as soon as you can.
On 29 August 2026 Gitea shipped 1.27.3. The official blog calls it the third patch of the 1.27 series: a large security batch covering Actions, the API, the package registry, and repository migration.
The post strongly recommends upgrading as soon as possible. CVE IDs below match that page. No CVSS scores were printed. The rest is a cluster check, not a runbook.
What the public post prints
| Cluster | Example CVE | What the blog says |
|---|---|---|
| Actions trust | CVE-2026-66877 | Concurrency group could dispatch unapproved fork jobs |
| Actions events | CVE-2026-71184 | Review-comment path skipped maintainer approval |
| Required checks | CVE-2026-66874 | Skipped workflow could satisfy a required status |
| Packages | CVE-2026-66849 | Restricted user could download a Limited user's registry |
| Migrate API | CVE-2026-70400 | Public-only token could create a private repo |
How to read the three clusters
- 1
This is a patch, not a feature launch
1.27.3 sits on the 1.27 line. The blog's lead is security plus UI and Actions bug fixes. Do not treat it as a new major version.
- 2
Actions trust is the first search term
Three listed CVEs sit on fork pull requests: unblocking jobs via a shared concurrency group, a missing pull-request attach on review comments, and a skipped workflow that can mark a required check as done. Self-hosted runners are named in CVE-2026-66877.
- 3
Visibility and token scope are a second list
Restricted accounts versus Limited-visibility users appear on issue search, SSH/GPG keys, activity feeds, packages, and organization listing. Token-scope gaps include org listing, workflow badges, migrate, and org repo create.
- 4
Uploads and migrations are a third list
Swift, Alpine, and Maven paths parsed or buffered before quota. GitLab and OneDev version probes could hold workers. Git hook directories were created 0777 before umask.
What else the changelog lists
Actions authoring
Step-level continue-on-error accepts an expression again. YAML anchors resolve once before the workflow is split per job. Matrix legs group by real job identity.
Packages and git
Swift Registry keeps SemVer prerelease identifiers. OpenPGP verification is not attempted with an SSH instance key when SIGNING_FORMAT is ssh.
Visibility behavior
Limited-visibility organizations grant the same unit read access to authenticated non-members as public organizations. That line is in the notable-fixes section, not the CVE list.
Limits
The post does not give a CVSS table, a forced-upgrade deadline, or a Cloud-specific status. Next step in the blog is the downloads page and the install docs. If you only needed a short meeting without another account wall, wbstorm is a browser room ID — see also privacy without an account and create or join a room.
# Sources
# Gitea Blog, 2026-08-29: Gitea 1.27.3 is released
# Changelog tag: 1.27.3 — 41 merged pull requestsIs this a new major version?
No. The blog calls it the third patch of the 1.27 series.
Did the project publish CVSS scores?
Not on that page. Identifiers and short technical summaries are listed; scores are not.
What should operators do, in the blog's words?
Upgrade as soon as possible. Binaries are on the downloads page; install docs are linked from the same post.