PatchSiren cyber security CVE debrief
CVE-2026-96580 Gitea CVE debrief
Gitea Actions is vulnerable to memory exhaustion through large static matrices. A user who can open a pull request from a fork could submit a small workflow file whose matrix expands to a very large number of jobs, consuming server memory and potentially terminating the Gitea process. This issue arises because Gitea expanded a workflow's static strategy.matrix into its full Cartesian product without a size limit when creating a run, before the fork pull request approval gate applied. No runner is required for exploitation. Static matrices above 256 combinations are now rejected before expansion, preventing potential memory exhaustion.
- Vendor
- Gitea
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-06
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-06
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for Gitea instances, especially those exposed to untrusted users, should assess exposure and prioritize upgrading to version 28.0.0 or later. This includes Gitea administrators, security teams, and operators who manage Gitea deployments. They should verify instance exposure, review official advisories, and plan for vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Why it matters
Defenders should prioritize verifying exposure of Gitea instances to untrusted users and upgrading to version 28.0.0 or later to prevent potential memory exhaustion and process termination.
- Potential memory exhaustion and process termination
- Need to verify exposure of Gitea instances to untrusted users
- Requirement to upgrade to version 28.0.0 or later
- Monitoring server memory usage for unusual patterns
Technical summary
Gitea expanded a workflow's static strategy.matrix into its full Cartesian product without a size limit when creating a run, before the fork pull request approval gate applied. A user who can open a pull request from a fork could submit a small workflow file whose matrix expands to a very large number of jobs, consuming server memory and potentially terminating the Gitea process. No runner is required. Static matrices above 256 combinations are now rejected before expansion.
Defensive priority
Defenders should prioritize verifying exposure of Gitea instances to untrusted users and upgrading to version 28.0.0 or later.
Recommended defensive actions
- Verify exposure of Gitea instances to untrusted users
- Upgrade to version 28.0.0 or later
- Monitor server memory usage for unusual patterns
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and source item provide details on the vulnerability, including the affected version and fixed version. The vulnerability allows a user who can open a pull request from a fork to submit a small workflow file whose matrix expands to a very large number of jobs, consuming server memory and potentially terminating the Gitea process. Evidence is limited to public CVE details and source item information. Defenders should verify Gitea instance exposure to untrusted users and review official advisories for specific version and
Sources and references
Verified primary and authoritative sources
-
CVE-2026-96580 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-96580
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-96580 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-96580
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Gitea Actions memory exhaustion through large static matrices
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/96xxx/CVE-2026-96580.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/go-gitea/gitea/security/advisories/GHSA-p3rv-cr5f-9gjh
Supplemental source - vendor-advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/go-gitea/gitea/pull/39295
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://blog.gitea.com/release-of-28.0.0/
Supplemental source - release-notes
-
Source reference
Unverified legacy reference
URL: https://github.com/go-gitea/gitea/releases/tag/v28.0.0
Supplemental source - release-notes
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.