CVE-2026-96399: Gitea
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
A repository's external issue tracker regular expression containing alternating capture groups could produce invalid slice indexes when Gitea rendered issue references, causing a runtime panic that terminated the Gitea process. A user who can edit a repository's external issue tracker settings could make any later rendering of matching content, such as viewing a README, crash the instance for all users.
Affected products
- Gitea Gitea: up to and including 1.27.3
Published 2026-10-06. Last modified 2026-10-07.