CVE-2026-26307
published 2026-07-03CVE-2026-26307: Gitea versions before 1.25.5 do not enforce a timeout on git grep searches, allowing expensive searches to consume server resources.
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.63%
47.4th percentile
Gitea versions before 1.25.5 do not enforce a timeout on git grep searches, allowing expensive searches to consume server resources.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gitea | gitea_open_source_git_server | < 1.25.5 | 1.25.5 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Gitea up to 1.25.4 resource consumption
vuldb·2026-07-04
CVE-2026-26307 [LOW] Gitea up to 1.25.4 resource consumption
A vulnerability, which was classified as problematic, was found in Gitea up to 1.25.4. Affected by this vulnerability is an unknown functionality. The manipulation results in resource consumption.
This vulnerability is identified as CVE-2026-26307. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.
GHSA
Gitea versions before 1.25.5 do not enforce a timeout on git grep searches, allowing expensive searches to consume server resources.
ghsa_unreviewed·2026-07-03
CVE-2026-26307 CWE-400 Gitea versions before 1.25.5 do not enforce a timeout on git grep searches, allowing expensive searches to consume server resources.
Gitea versions before 1.25.5 do not enforce a timeout on git grep searches, allowing expensive searches to consume server resources.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-03
Published