PT-2026-55654 · Gitea+4 · Gitea Open Source Git Server+3

·

CVE-2026-58421

·

Published

2026-07-03

·

Updated

2026-08-10

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description An unauthenticated Regular Expression Denial of Service (ReDoS) exists due to improper pattern matching within the CODEOWNERS file processing. This allows a remote attacker to cause a denial of service by providing a specially crafted pattern that triggers excessive CPU consumption during the matching process.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-58421
GHSA-V96J-25GV-G2W9
GO-2026-6077
OPENSUSE-SU-2026:21551-1
SUSE-SU-2026:23216-1
SUSE-SU-2026:23227-1

Affected Products

Gitea Open Source Git Server
Code.Gitea.Io/Gitea
Gitea
Govulncheck-Vulndb