Denial of Service Vulnerability in Gitea Product from Gitea
CVE-2026-42931

Currently unrated

Key Information:

Vendor

Gitea

Vendor
CVE Published:
13 August 2026

What is CVE-2026-42931?

A Denial of Service vulnerability exists in the Gitea product due to unbounded execution of the io.ReadAll function within the NPM package tag endpoint. This can potentially lead to resource exhaustion, disrupting service availability. It is crucial for users and administrators to apply necessary updates and patches to mitigate the risks associated with this vulnerability.

Affected Version(s)

Gitea Open Source Git Server 0 <= 1.24

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tricta
.