Resource exhaustion in Gitea - CVE-2026-56755
Published: July 14, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in ParseControlFile when processing an uploaded .deb file containing a crafted compressed control.tar.gz member. A remote user can upload a specially crafted package to cause a denial of service.
The issue is triggered before content validation runs.