PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-96580 Gitea CVE debrief

Gitea Actions is vulnerable to memory exhaustion through large static matrices. A user who can open a pull request from a fork could submit a small workflow file whose matrix expands to a very large number of jobs, consuming server memory and potentially terminating the Gitea process. This issue arises because Gitea expanded a workflow's static strategy.matrix into its full Cartesian product without a size limit when creating a run, before the fork pull request approval gate applied. No runner is required for exploitation. Static matrices above 256 combinations are now rejected before expansion, preventing potential memory exhaustion.

Vendor
Gitea
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-06
Original CVE updated
2026-10-07
Advisory published
2026-10-06
Advisory updated
2026-10-07

Who should care

Defenders responsible for Gitea instances, especially those exposed to untrusted users, should assess exposure and prioritize upgrading to version 28.0.0 or later. This includes Gitea administrators, security teams, and operators who manage Gitea deployments. They should verify instance exposure, review official advisories, and plan for vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Why it matters

Defenders should prioritize verifying exposure of Gitea instances to untrusted users and upgrading to version 28.0.0 or later to prevent potential memory exhaustion and process termination.

  • Potential memory exhaustion and process termination
  • Need to verify exposure of Gitea instances to untrusted users
  • Requirement to upgrade to version 28.0.0 or later
  • Monitoring server memory usage for unusual patterns

Technical summary

Gitea expanded a workflow's static strategy.matrix into its full Cartesian product without a size limit when creating a run, before the fork pull request approval gate applied. A user who can open a pull request from a fork could submit a small workflow file whose matrix expands to a very large number of jobs, consuming server memory and potentially terminating the Gitea process. No runner is required. Static matrices above 256 combinations are now rejected before expansion.

Defensive priority

Defenders should prioritize verifying exposure of Gitea instances to untrusted users and upgrading to version 28.0.0 or later.

Recommended defensive actions

  • Verify exposure of Gitea instances to untrusted users
  • Upgrade to version 28.0.0 or later
  • Monitor server memory usage for unusual patterns
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and source item provide details on the vulnerability, including the affected version and fixed version. The vulnerability allows a user who can open a pull request from a fork to submit a small workflow file whose matrix expands to a very large number of jobs, consuming server memory and potentially terminating the Gitea process. Evidence is limited to public CVE details and source item information. Defenders should verify Gitea instance exposure to untrusted users and review official advisories for specific version and

Sources and references

Verified primary and authoritative sources

  • CVE-2026-96580 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-96580

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-96580 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-96580

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Gitea Actions memory exhaustion through large static matrices

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/96xxx/CVE-2026-96580.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/go-gitea/gitea/security/advisories/GHSA-p3rv-cr5f-9gjh

    Supplemental source - vendor-advisory

  • Source reference

    Unverified legacy reference

    URL: https://github.com/go-gitea/gitea/pull/39295

    Supplemental source - patch

  • Source reference

    Unverified legacy reference

    URL: https://blog.gitea.com/release-of-28.0.0/

    Supplemental source - release-notes

  • Source reference

    Unverified legacy reference

    URL: https://github.com/go-gitea/gitea/releases/tag/v28.0.0

    Supplemental source - release-notes

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.