Description
Gitea expanded a workflow's static `strategy.matrix` into its full Cartesian product without a size limit when creating a run, before the fork pull request approval gate applied. A user who can open a pull request from a fork could submit a small workflow file whose matrix expands to a very large number of jobs, consuming server memory and potentially terminating the Gitea process. No runner is required. Static matrices above 256 combinations are now rejected before expansion.
Published: 2026-10-06
Score: n/a
EPSS: n/a
KEV: No
Impact: Memory exhaustion leading to denial of service
Action: Apply Update
AI Analysis

Impact

Gitea expands a workflow’s static matrix into its full cartesian product without imposing a size limit when a run is created, before the fork pull request approval gate is enforced. A contributor who can open a pull request from a fork can supply a workflow file with a small matrix that expands to a very large number of jobs, consuming all server RAM and potentially terminating the Gitea process; no runner or external action is required for the attack.

Affected Systems

The issue impacts the Gitea platform, specifically versions before the 28.0.0 release, because those releases lack the 256‑combination hard cap on static matrices. Any Gitea instance that allows pull requests from forks to modify or create workflow files is at risk.

Risk and Exploitability

The vulnerability is highly exploitable for any system permitting forked pull requests containing workflow files. An attacker can trigger a denial‑of‑service with minimal effort, causing service disruption for all repositories served by the instance. The public CVSS score is absent and EPSS data is unavailable; however, the severity is evident from the memory exhaustion impact. The vulnerability is not catalogued in the CISA KEV, but the potential for widespread service interruption demands prompt remediation. The attack vector is inferred to be a forked pull request that is accepted without proper matrix‑size validation.

Generated by OpenCVE AI on October 6, 2026 at 22:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Gitea to version 28.0.0 or later, which imposes a 256‑combination limit on static matrices.
  • Restrict or disable pull requests from forks that can create or alter workflow files, or require manual approval before merging such changes.
  • Configure Gitea’s action dispatcher to enforce an explicit matrix‑size policy or increase server hard memory limits and monitor for abnormal spikes.

Generated by OpenCVE AI on October 6, 2026 at 22:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Description Gitea expanded a workflow's static `strategy.matrix` into its full Cartesian product without a size limit when creating a run, before the fork pull request approval gate applied. A user who can open a pull request from a fork could submit a small workflow file whose matrix expands to a very large number of jobs, consuming server memory and potentially terminating the Gitea process. No runner is required. Static matrices above 256 combinations are now rejected before expansion.
Title Gitea Actions memory exhaustion through large static matrices
Weaknesses CWE-400
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Gitea

Published:

Updated: 2026-10-06T19:25:33.619Z

Reserved: 2026-10-04T21:59:53.570Z

Link: CVE-2026-96580

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T20:17:35.600

Modified: 2026-10-06T20:17:35.600

Link: CVE-2026-96580

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T22:45:07Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption