CVE-2026-96399
N/A
N/A
Summary
A repository's external issue tracker regular expression containing alternating capture groups could produce invalid slice indexes when Gitea rendered issue references, causing a runtime panic that terminated the Gitea process. A user who can edit a repository's external issue tracker settings could make any later rendering of matching content, such as viewing a README, crash the instance for all users.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Gitea | Gitea | 0 <= 1.27.3 | affected |
Weaknesses
- CWE-125: CWE-125: Out-of-bounds Read
- CWE-248: CWE-248: Uncaught Exception
References
- https://github.com/go-gitea/gitea/security/advisories/GHSA-mw6q-qj47-9g5q
- https://github.com/go-gitea/gitea/pull/39354
- https://blog.gitea.com/release-of-28.0.0/
- https://github.com/go-gitea/gitea/releases/tag/v28.0.0
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.