CVE-2026-42931 | Gitea up to 1.24 NPM Package Tag Endpoint io.ReadAll denial of service
A vulnerability, which was classified as problematic, has been found in Gitea up to 1.24. This affects the function io.ReadAll of the component NPM Package Tag Endpoint. This manipulation causes denial of service.
This vulnerability is tracked as CVE-2026-42931. The attack is possible to be carried out remotely. No exploit exists.VulDB Recent EntriesRead More