CVE-2026-96580
Gitea Actions memory exhaustion through large static matrices
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Gitea expanded a workflow's static `strategy.matrix` into its full Cartesian product without a size limit when creating a run, before the fork pull request approval gate applied. A user who can open a pull request from a fork could submit a small workflow file whose matrix expands to a very large number of jobs, consuming server memory and potentially terminating the Gitea process. No runner is required. Static matrices above 256 combinations are now rejected before expansion.
| CWE | CWE-400 |
| Vendor | gitea |
| Product | gitea |
| Published | Oct 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for gitea gitea
Be the first to know when new unknown vulnerabilities affecting gitea gitea are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Gitea / Gitea
0 โค 1.27.3
References
Credits
๐ https://github.com/smoke-wolf https://github.com/Kushalkhemka https://github.com/mayank-jangid-moon https://github.com/skigeek16 https://github.com/opensec-intelligence https://github.com/silverwind https://github.com/bircni