UNKNOWN Go
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev
GO-2026-6037 · CVE-2026-56755 · GHSA-6hm7-3pwj-22rm
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev
References
- ADVISORY https://github.com/go-gitea/gitea/security/advisories/GHSA-6hm7-3pwj-22rm
- WEB https://github.com/go-gitea/gitea/commit/de4b8277e9cb576f2315fb03b5ab6478b42a1d31
- WEB https://github.com/go-gitea/gitea/commit/f69e15afe7496cc62e96dab244629c69eb31a7bf
- WEB https://github.com/go-gitea/gitea/pull/38406
- WEB https://github.com/go-gitea/gitea/pull/38426
- WEB https://github.com/go-gitea/gitea/releases/tag/v1.27.0
Ready to move
Start Securing
Free, no credit card | First findings in minutes