Junglewise Threat Intelligence

CVE-2026-26307: Gitea uncontrolled resource consumption in git grep searches

CVE-2026-26307 · Severity: high · CVSS 7.5 · Published 2026-07-03

Technologies: code.gitea.io/gitea (Go), Gitea. Vendors: Go, Gitea.

Executive brief

Gitea is a self-hosted Git service used by organizations to manage source code repositories. A weakness in the git grep search feature allows unauthenticated attackers to submit computationally expensive searches that consume server CPU and memory, causing the service to become slow or unavailable for legitimate users. An attacker can trigger this repeatedly to deny service to an entire Gitea instance.

Technical details

The vulnerability is an uncontrolled resource consumption issue (CWE-400) in Gitea's git grep search implementation. Versions before 1.25.5 lack a timeout mechanism on grep operations, allowing an attacker to submit regex patterns or search queries designed to consume excessive CPU time. The attack is network-based, requires no authentication or privileges, and can be triggered without user interaction. An unauthenticated attacker can repeatedly invoke expensive grep searches via the web API or interface to exhaust server resources and cause denial of service. The fix adds a timeout constraint to grep operations, released in version 1.25.5 (March 2026) and backported to the 1.25.x release branch.

Affected products

  • Gitea Gitea < 1.25.5

Timeline

  • 2026-07-03: disclosed: Published to GitHub Advisory Database
  • 2026-03-16: patched: Fixed in Gitea 1.25.5 released March 16, 2026

References

Related threats