CVE-2026-104633: Gitea
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
When migrating a repository from another Gitea instance, Gitea used the page size reported in the source server's API settings to end its paginated downloads. A source that reported `max_response_items` as `0` made these loops run indefinitely and grow server memory until it was exhausted. Any user who can migrate repositories could point a migration at a server they control and cause a denial of service.
Affected products
- Gitea Gitea: up to and including 28.0.0
Published 2026-10-06. Last modified 2026-10-07.