Denial of Service Vulnerability in Gitea by Gitea
CVE-2026-56755

Currently unrated

Key Information:

Vendor

Gitea

Vendor
CVE Published:
13 August 2026

What is CVE-2026-56755?

A vulnerability exists within Gitea that may lead to Denial of Service due to inefficient string concatenation during the Debian package upload process. This flaw can cause significant CPU and memory exhaustion, impacting the application's performance and availability. Exploitation of this issue allows an attacker to create a scenario where legitimate user interactions are hindered, ultimately crippling the functionality of Gitea. It is essential for users to review the security advisory linked below and update to the latest patch version to safeguard their instances.

Affected Version(s)

Gitea Open Source Git Server 0 <= 1.26.4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

AdamKorcz
.