Resource exhaustion in Gitea - CVE-2026-60021

 

Resource exhaustion in Gitea - CVE-2026-60021

Published: August 31, 2026


Vulnerability identifier: #VU146357
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-60021
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in the GitLab migration downloader version probe when requesting the remote /api/v4/version endpoint. A remote user can operate a GitLab-compatible server that keeps the response open indefinitely to cause a denial of service.

Only the initial version probe is unaffected by the migration task context, so cancellation does not interrupt the request. Exploitation is reachable by any authenticated user who can start a repository migration.


Affected software

Gitea

How to mitigate CVE-2026-60021

Install security update from vendor's website.

Gitea - update to 1.27.3

External References

Related Security Bulletins