gitea 1.27.3 — 26-CVE security batch incl. Actions approval bypasses (high) · the git forge itself
1.27.2-rootless → 1.27.3-rootless fixes 26 CVEs — the deterministic scan's 24, plus CVE-2026-62925 (adjudicated FIXED from the vendor's patch note) and CVE-2026-70406 (named in the vendor security post, not yet in GHSA). Five are rated high per the vendor, four of those with GHSA advisories so far: CVE-2026-60010, -66877, -68957, -71184 — spanning fork-PR Actions approval bypasses (code execution where self-hosted runners are enabled), restricted-user data leaks, package-registry access control and token-scope enforcement. The count is a floor: sidecar advisory CVE-2025-68939 could not be judged and is unmeasured, not unaffected. postgres is deliberately held at 15 (a DB-major bump needs an operator dump/restore). !testme GREEN at build 1306 — merge, then abra recipe release
gitea -z. The unrelated app.ini fix PR #4 (green at 1250) is also open.
26.7.2 → 26.7.3 closes 22 CVEs named in the vendor changelog: an unsigned signed-JWT assertion bypass (CVE-2026-16093), LDAP certificate hostname verification (CVE-2026-35563), an incomplete redirect_uri fix (CVE-2026-18209), FGAP/role authorization bypasses (CVE-2026-16105, -16106, -18570, -18571), user PII disclosure in GET /roles/{role}/users (CVE-2026-17059), raw reCAPTCHA secret exposure (CVE-2026-16104), and an incomplete fix of a path traversal (CVE-2026-19729), among others. Operators deploying from ≤26.7.1 additionally land critical CVE-2026-18963 (unauthenticated account takeover via reset-credentials bypass, fixed in 26.7.2 — already carried in main). Known 26.7.x watch-items, not blockers: admin-API cost growth with many realms (#51554) and post-upgrade high CPU (#51523). No migrations; mariadb 12.3 held. !testme GREEN at build 1307.
lasuite-meet — nginx 1.31.3 high batch + redis 8.10.1 security release (high) · now CI-verified
The v1.21.0 → v1.29.0 PR crosses nginx 1.31.2 → 1.31.4, picking up the three high nginx CVEs fixed in 1.31.3 (CVE-2026-42533, -56434, -60005) that last week's cert outage left unverified, plus redis 8.8.0 → 8.10.1 — a SECURITY release fixing CVE-2026-62356 (heap out-of-bounds write in CMSketch RDB loading) and several further flaws the vendor names without CVE ranges, so the count of 4 is a floor. livekit v1.13.6 rides along (its only default change is the H.264 baseline codec leaving the enabled list — standard clients unaffected). AUTO_MIGRATIONS handled the database. !testme GREEN at build 1311 — last week's blocked flag is cleared.
discourse 2026.7.2 — eight vendor security-fix groups, severities undisclosed · internet-facing
The 2026.7.1 → 2026.7.2 patch on the 2026.7 ESR line carries eight security-fix groups (18 SECURITY-tagged commits): stored XSS in video placeholders and email video titles, iframe allowlist / userinfo / wildcard fixes, embed-URL escaping in the footer, LIKE-metachar escaping on upload paths, hidden-post-revision reconstruction blocking, anonymous-cache-key partitioning, and more. Upstream publishes no CVE IDs for this release (advisory scan: 0; the one candidate, CVE-2025-53016, predates the window and was adjudicated already-fixed in 2026.7.1) — so the table's 0 means "no identified CVEs", not "no security content". Rails migrations auto-run on boot; no config changes. !testme GREEN at build 1303 (a duplicate trigger also resolved green at 1305).