Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
operational-disruptioninternet-facing-service-vulnerabilityproof-of-concept-releasebreach-disclosure-notification

GNU Savannah Patched After Reported Vulnerabilities Triggered Service Disruption

Updated 12h agoFirst seen Jun 20, 20264 sources

GNU Savannah, the software forge and hosting platform used by GNU and other free software projects, suffered a security incident that disrupted services and forced administrators to take systems offline while recovery work proceeded. The Free Software Foundation said security researchers from Hacktron had reported vulnerabilities in early May and demonstrated an exploit, after which FSF, GNU, and volunteer staff patched all reported issues along with additional security problems submitted during the review.

FSF said its investigation found no evidence that sensitive project data or credentials were accessed and no indication that Savannah’s software supply chain was compromised. Service was later restored in stages, with some functions remaining limited during recovery, and FSF said it would take additional precautionary steps, notify Savannah-hosted projects and other Savane operators, and publish a fuller incident report within 30 days.

Share:
GNU Savannah Patched After Reported Vulnerabilities Triggered Service Disruption
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Jun 19, 20262d ago

FSF issues statement on Savannah security reports

On June 19, 2026, FSF stated that it found no evidence sensitive project data or credentials were accessed and no indication Savannah’s software supply chain was compromised. It also said it would take additional precautionary steps, contact hosted projects and other Savane operators, and publish a fuller incident report within 30 days.

Statement regarding GNU Savannah security reports - Free Software Foundation - Working together for free software

FSF patches all reported GNU Savannah issues

After receiving the reports, FSF said it worked with the researchers and GNU/FSF volunteers and staff to patch all reported vulnerabilities, including additional security issues later submitted by the researchers.

Statement regarding GNU Savannah security reports - Free Software Foundation - Working together for free software

Hacktron reports Savannah vulnerabilities and demonstrates exploit

The Free Software Foundation said security researchers from Hacktron reported vulnerabilities in GNU Savannah in early May and demonstrated an exploit against the platform.

Statement regarding GNU Savannah security reports - Free Software Foundation - Working together for free software
Jun 18, 20263d ago

GNU Savannah services begin returning after restoration work

Following the prolonged outage, GNU Savannah resumed operation after recovery efforts, with some services restored gradually and others still limited or returning in stages.

���� ��� ����������� � ����������� ���������� � �������� ���������� ���� GNU Savannah

GNU Savannah disruption leads administrators to take systems offline

GNU Savannah suffered a compromise-related service disruption that led administrators to take systems offline while they investigated and began restoration work. The outage affected infrastructure used to host and manage GNU and other free software projects.

���� ��� ����������� � ����������� ���������� � �������� ���������� ���� GNU Savannah
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

4 LINKEDOpen in app
Affected products
2 linked
GithubGitlab
Organizations
2 linked
Free Software FoundationHacktron
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

GNU Savannah Patched After Reported Vulnerabilities Triggered Service Disruption | Mallory