Allocation of Resources Without Limits or Throttling in Gitea - CVE-2026-73273
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the Maven checksum upload handler when processing checksum upload requests. A remote user can send a specially crafted checksum upload request to cause a denial of service.
Exploitation is reachable through checksum extension uploads such as .md5, .sha1, .sha256, and .sha512, and requires Maven package write access.