Reference page — cumulative record through Saturday, October 3, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-60004
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U H H H 9.8 .2399 97.8 YES
AFFECTED
Product Versions Fixed
Gitea 1.17 – —
TIMELINE
Jul 8 Reserved by mitre
Aug 26 EXPLOIT PUBLISHED — CVE-2026-60004 (Gitea). Public exploit reference added.
Aug 26 ADDED TO KEV — CVE-2026-60004 (Gitea). Remediation due August 28, 2026.
Aug 26 Published (CNA: mitre)
Aug 29 DUE DATE PASSED — CVE-2026-60004 (Gitea). CISA remediation deadline was August 28, 2026; still in catalog.
Description
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
Lifecycle
Complete event history — 5 events, chronological
| Date | Event | Detail |
| July 8, 2026 | Reserved | Reserved by mitre |
| August 26, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-60004 (Gitea). Public exploit reference added. |
| August 26, 2026 | KEV ADDED | ADDED TO KEV — CVE-2026-60004 (Gitea). Remediation due August 28, 2026. |
| August 26, 2026 | Published | Published (CNA: mitre) |
| August 29, 2026 | DUE DATE PASSED | DUE DATE PASSED — CVE-2026-60004 (Gitea). CISA remediation deadline was August 28, 2026; still in catalog. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Gitea | Gitea | — | 1.17 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-60004 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Saturday, October 3, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.