CVE-2026-26307: Gitea git grep search lacks a timeout
Published Jul 3, 2026
·Updated
Gitea versions before 1.25.5 do not enforce a timeout on git grep searches, allowing expensive searches to consume server resources.
Affected Software
1 affected component
Gitea Gitea<1.25.5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
giteato a version that resolves this vulnerability.Fixed in 1.25.5
Event History
Jul 3, 2026
CVE Published
via MITRE·08:19 PM
Data Sourced
via MITRE·08:19 PM
DescriptionWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-26307?
CVE-2026-26307 has a risk score of 26, indicating a significant vulnerability.
2
How do I fix CVE-2026-26307?
To fix CVE-2026-26307, upgrade Gitea to version 1.25.5 or later.
3
What does CVE-2026-26307 affect?
CVE-2026-26307 affects Gitea versions prior to 1.25.5.
4
What is the impact of CVE-2026-26307?
CVE-2026-26307 allows git grep searches to consume excessive server resources due to the lack of a timeout.
5
When was CVE-2026-26307 published?
CVE-2026-26307 was published on July 3, 2026.