Denial of Service Vulnerability in Gitea Locale Middleware
CVE-2026-58436

Currently unrated

Key Information:

Vendor

Gitea

Vendor
CVE Published:
13 August 2026

What is CVE-2026-58436?

A vulnerability in Gitea's Locale middleware allows for a denial of service when handling unauthenticated requests. The issue arises due to quadratic-time complexity in processing the Accept-Language header, potentially leading to service disruption under certain conditions. This can be exploited by attackers to overwhelm the server, impacting availability for legitimate users.

Affected Version(s)

Gitea Open Source Git Server 0 <= 1.26.4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

tonghuaroot
.