Input validation error in Gitea - CVE-2026-59763
Published: July 14, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper input validation in the Arch package registry metadata parser and repository index generation when processing uploaded Arch package archives. A remote user can upload a specially crafted package archive with a large number of file entries to cause a denial of service.
The issue requires package publishing permission and can amplify server-side CPU, memory, storage, and repository index processing relative to the compressed upload size.