Denial of Service Vulnerability in Gitea During Repository Migration
CVE-2026-104633

Currently unrated

Key Information:

Vendor

Gitea

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-104633?

Gitea has a vulnerability affecting repository migration when an external Gitea instance is linked for data transfer. Specifically, the issue arises when the source server reports a maximum response items setting of zero, causing the receiving Gitea instance to enter an infinite loop during paginated downloads. This leads to exhaustion of server memory resources, potentially culminated in a Denial of Service situation. Users with the ability to migrate repositories can exploit this vulnerability by targeting Gitea servers they control, resulting in operational disruptions.

Affected Version(s)

Gitea 0 <= 28.0.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

https://github.com/kewmine
https://github.com/silverwind
https://github.com/bircni
.