Impact
Unbounded Arch package file metadata in Gitea can lead to resource amplification when a package is uploaded. The description does not detail the exact exploit chain, but it is inferred that an attacker who can upload packages could craft metadata that forces the server to consume excessive CPU, memory or network resources, resulting in a possible denial‑of‑service condition. The flaw relates to improper access control (CWE‑284).
Affected Systems
The vulnerability affects the Gitea Open Source Git Server. No specific version information is supplied in the advisory, so any installation that accepts package uploads on the Arch package endpoint before the issue is corrected is considered at risk.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity. The EPSS score is not available and the issue is not listed in the CISA KEV catalog. It is inferred that the attack vector is remote via the HTTP upload endpoint for Arch packages; an attacker would need upload privileges to exploit the flaw. The CVE description does not mention rate limiting, so that claim is not supported. Any Gitea instance that accepts package uploads on the Arch package endpoint before the issue is corrected remains vulnerable.
OpenCVE Enrichment
Github GHSA