Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-58436

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 7.5

Описание

ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests

A flaw was found in Gitea. An unauthenticated remote attacker could exploit a quadratic-time algorithm in the ParseAcceptLanguage function, specifically within the Locale middleware. This vulnerability allows an attacker to send specially crafted requests, leading to excessive resource consumption and a Denial of Service (DoS) condition, making the service unavailable to legitimate users.

Отчет

This is an Important denial of service vulnerability in Gitea. An unauthenticated remote attacker can exploit a quadratic-time algorithm in the ParseAcceptLanguage function, leading to excessive resource consumption and service unavailability.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Pipelinesopenshift-pipelines-clientNot affected
OpenShift Pipelinesopenshift-pipelines/pipelines-cli-tkn-rhel9Not affected
OpenShift Pipelinesopenshift-pipelines/pipelines-opc-rhel9Not affected
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-cli-rhel9Not affected
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-controller-rhel9Not affected
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-watcher-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1333
https://bugzilla.redhat.com/show_bug.cgi?id=2515473code.gitea.io/gitea: Gitea: Denial of Service via ParseAcceptLanguage and Locale middleware on unauthenticated requests

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
20 дней назад

ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests

CVSS3: 7.5
redos
20 дней назад

Уязвимость gitea

CVSS3: 7.5
redos
20 дней назад

Уязвимость gitea

github
около 1 месяца назад

Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests

7.5 High

CVSS3