Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-104633

UNKNOWN NVD
CVSS Score 0
Severity UNKNOWN
Published Oct 06, 2026
Vendor unknown

Description

When migrating a repository from another Gitea instance, Gitea used the page size reported in the source server's API settings to end its paginated downloads. A source that reported `max_response_items` as `0` made these loops run indefinitely and grow server memory until it was exhausted. Any user who can migrate repositories could point a migration at a server they control and cause a denial of service.

References