CVE-2026-104633: Gitea

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

When migrating a repository from another Gitea instance, Gitea used the page size reported in the source server's API settings to end its paginated downloads. A source that reported `max_response_items` as `0` made these loops run indefinitely and grow server memory until it was exhausted. Any user who can migrate repositories could point a migration at a server they control and cause a denial of service.

Affected products

  • Gitea Gitea: up to and including 28.0.0

Published 2026-10-06. Last modified 2026-10-07.