Resource exhaustion in Gitea - CVE-2026-60018
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the OneDev migration downloader when processing the /~api/version/server response during a repository migration. A remote user can point a migration to a malicious OneDev-compatible server that returns an arbitrarily large or never-ending response body to cause a denial of service.
The issue is reachable through web, API, and background-task migration paths.