---
id: CVE-2026-104633
title: >-
  When migrating a repository from another Gitea instance, Gitea used the page
  size reported in the source server's API settings to end its paginated
  downloads
summary: >-
  When migrating a repository from another Gitea instance, Gitea used the page
  size reported in the source server's API settings to end its paginated
  downloads. A source that reported `max_response_items` as `0` made these loops
  run indefi…
severity: none
cwe:
  - CWE-400
  - CWE-835
vendor: Gitea
product: gitea.dev
affected:
  - gitea.dev <= 28.0.0
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T22:17:01.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104633'
references:
  - url: 'https://blog.gitea.com/release-of-28.1.0/'
    label: 88ee5874-cf24-4952-aea0-31affedb7ff2
  - url: 'https://github.com/go-gitea/gitea/pull/39501'
    label: 88ee5874-cf24-4952-aea0-31affedb7ff2
  - url: 'https://github.com/go-gitea/gitea/pull/39507'
    label: 88ee5874-cf24-4952-aea0-31affedb7ff2
  - url: 'https://github.com/go-gitea/gitea/releases/tag/v28.1.0'
    label: 88ee5874-cf24-4952-aea0-31affedb7ff2
  - url: 'https://github.com/go-gitea/gitea/security/advisories/GHSA-jj5r-9rpc-8h6h'
    label: 88ee5874-cf24-4952-aea0-31affedb7ff2
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T22:23:15.964Z'
---

## Overview

When migrating a repository from another Gitea instance, Gitea used the page size reported in the source server's API settings to end its paginated downloads. A source that reported `max_response_items` as `0` made these loops run indefinitely and grow server memory until it was exhausted. Any user who can migrate repositories could point a migration at a server they control and cause a denial of service.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
