Resource exhaustion in Gitea - CVE-2026-73130
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the repository creation gitignores field when processing repository creation requests with auto-init enabled. A remote user can submit an overly long comma-separated value to cause a denial of service.
The issue is reachable through the repository creation form and the user and organization repository creation API endpoints only when automatic repository initialization is enabled.