Gitea 1.27.3 security patches: 2026 Actions and API fixes explained

Gitea 1.27.3 shipped on 29 August with a large security batch. The official blog flags Actions trust, API token scopes, package visibility, and migration hangs. Forty-one pull requests. Upgrade as soon as you can.

On 29 August 2026 Gitea shipped 1.27.3. The official blog calls it the third patch of the 1.27 series: a large security batch covering Actions, the API, the package registry, and repository migration.

The post strongly recommends upgrading as soon as possible. CVE IDs below match that page. No CVSS scores were printed. The rest is a cluster check, not a runbook.

Official blogCVE clustersUpgrade note

What the public post prints

1.27.3
Third patch of the 1.27 series
8/29
Release date on the Gitea blog
41
Merged pull requests in the changelog
ClusterExample CVEWhat the blog says
Actions trustCVE-2026-66877Concurrency group could dispatch unapproved fork jobs
Actions eventsCVE-2026-71184Review-comment path skipped maintainer approval
Required checksCVE-2026-66874Skipped workflow could satisfy a required status
PackagesCVE-2026-66849Restricted user could download a Limited user's registry
Migrate APICVE-2026-70400Public-only token could create a private repo

How to read the three clusters

  1. 1

    This is a patch, not a feature launch

    1.27.3 sits on the 1.27 line. The blog's lead is security plus UI and Actions bug fixes. Do not treat it as a new major version.

  2. 2

    Actions trust is the first search term

    Three listed CVEs sit on fork pull requests: unblocking jobs via a shared concurrency group, a missing pull-request attach on review comments, and a skipped workflow that can mark a required check as done. Self-hosted runners are named in CVE-2026-66877.

  3. 3

    Visibility and token scope are a second list

    Restricted accounts versus Limited-visibility users appear on issue search, SSH/GPG keys, activity feeds, packages, and organization listing. Token-scope gaps include org listing, workflow badges, migrate, and org repo create.

  4. 4

    Uploads and migrations are a third list

    Swift, Alpine, and Maven paths parsed or buffered before quota. GitLab and OneDev version probes could hold workers. Git hook directories were created 0777 before umask.

What else the changelog lists

01

Actions authoring

Step-level continue-on-error accepts an expression again. YAML anchors resolve once before the workflow is split per job. Matrix legs group by real job identity.

02

Packages and git

Swift Registry keeps SemVer prerelease identifiers. OpenPGP verification is not attempted with an SSH instance key when SIGNING_FORMAT is ssh.

03

Visibility behavior

Limited-visibility organizations grant the same unit read access to authenticated non-members as public organizations. That line is in the notable-fixes section, not the CVE list.

Limits

The post does not give a CVSS table, a forced-upgrade deadline, or a Cloud-specific status. Next step in the blog is the downloads page and the install docs. If you only needed a short meeting without another account wall, wbstorm is a browser room ID — see also privacy without an account and create or join a room.

# Sources
# Gitea Blog, 2026-08-29: Gitea 1.27.3 is released
# Changelog tag: 1.27.3 — 41 merged pull requests
Is this a new major version?

No. The blog calls it the third patch of the 1.27 series.

Did the project publish CVSS scores?

Not on that page. Identifiers and short technical summaries are listed; scores are not.

What should operators do, in the blog's words?

Upgrade as soon as possible. Binaries are on the downloads page; install docs are linked from the same post.

Create room