github RayLabsHQ/gitea-mirror v3.35.1

7 hours ago

Security patch. No functional changes since v3.35.0.

Security

Advisories published on 2026-09-08 affected the versions this release line was pinning, so the dependency floors moved up. The application image and the documentation site are both covered.

  • Astro to 7.2.8 or newer (7.3.2 resolved): remote code execution through AVIF image optimization (GHSA-26w7-cxv4-gfx2, critical), and an authorization bypass from a missing path segment boundary check when stripping the configured base (GHSA-376h-93r7-7g6f).
  • @xmldom/xmldom to 0.8.15: eight parser and serializer issues, CVE-2026-83605 through CVE-2026-83619. It reaches the image through the SAML dependencies of the SSO provider.
  • sharp to 0.35.4 (libheif), svgo to 4.1.0 (removeScripts sanitization) and js-yaml to 4.3.2 (merge key CPU use).

The image scan on this build reports no vulnerable packages.

Notes

  • Nothing to do on upgrade beyond pulling the new image. No migration, no configuration change.
  • One image scan alert stays open on the repository: CVE-2026-85091 in zlib, which Debian has not fixed in any release. It sits in the gz* file writing API, which nothing in the image uses, and it is covered by the VEX statement under .vex/.

Full Changelog: v3.35.0...v3.35.1

Don't miss a new gitea-mirror release

NewReleases is sending notifications on new releases.