Resource exhaustion in Gitea - CVE-2026-73130

 

Resource exhaustion in Gitea - CVE-2026-73130

Published: August 31, 2026


Vulnerability identifier: #VU146362
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-73130
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in the repository creation gitignores field when processing repository creation requests with auto-init enabled. A remote user can submit an overly long comma-separated value to cause a denial of service.

The issue is reachable through the repository creation form and the user and organization repository creation API endpoints only when automatic repository initialization is enabled.


Affected software

Gitea

How to mitigate CVE-2026-73130

Install security update from vendor's website.

Gitea - update to 1.27.3

External References

Related Security Bulletins