VYPR
Unrated severityNVD Advisory· Published Oct 6, 2026

CVE-2026-96580

CVE-2026-96580

Description

Gitea expanded a workflow's static strategy.matrix into its full Cartesian product without a size limit when creating a run, before the fork pull request approval gate applied. A user who can open a pull request from a fork could submit a small workflow file whose matrix expands to a very large number of jobs, consuming server memory and potentially terminating the Gitea process. No runner is required. Static matrices above 256 combinations are now rejected before expansion.

Affected products

2
  • Go Gitea/Giteareferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.

CVE-2026-96580 · VYPR