CVE-2026-95112

medium

Description

When processing issue and comment bodies, Gitea scanned the entire preceding text for action keywords such as "closes" or "fixes" once per Markdown link, giving processing time quadratic in the input size. An authenticated user able to submit issue or comment content could send a crafted body of about 1 MB that keeps a CPU core busy for several minutes while holding a database transaction open.

References

https://github.com/go-gitea/gitea/security/advisories/GHSA-467c-4w7p-8427

https://github.com/go-gitea/gitea/releases/tag/v28.0.0

https://github.com/go-gitea/gitea/pull/39396

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-93920

https://blog.gitea.com/release-of-28.0.0/

Details

Source: Mitre, NVD

Published: 2026-10-06

Updated: 2026-10-08

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 6.5

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00305