Allocation of Resources Without Limits or Throttling in Gitea - CVE-2026-42931
Published: July 14, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the AddPackageTag NPM package tag API endpoint when handling a crafted HTTP PUT request body. A remote user can send a single large request body to cause a denial of service.
No package needs to exist for exploitation, and concurrent requests can repeatedly crash the server after automatic restarts.