---
id: CVE-2026-95112
title: >-
  When processing issue and comment bodies, Gitea scanned the entire preceding
  text for action keywords such as "closes" or "fixes" once per Markdown link,
  giving processing time quadratic in the input size
summary: >-
  When processing issue and comment bodies, Gitea scanned the entire preceding
  text for action keywords such as "closes" or "fixes" once per Markdown link,
  giving processing time quadratic in the input size. An authenticated user able
  to s…
severity: none
vendor: Gitea
product: gitea.dev
affected:
  - gitea.dev <= 1.27.3
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T20:17:34.963'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-95112'
references:
  - url: 'https://blog.gitea.com/release-of-28.0.0/'
    label: 88ee5874-cf24-4952-aea0-31affedb7ff2
  - url: 'https://github.com/go-gitea/gitea/pull/39396'
    label: 88ee5874-cf24-4952-aea0-31affedb7ff2
  - url: 'https://github.com/go-gitea/gitea/releases/tag/v28.0.0'
    label: 88ee5874-cf24-4952-aea0-31affedb7ff2
  - url: 'https://github.com/go-gitea/gitea/security/advisories/GHSA-467c-4w7p-8427'
    label: 88ee5874-cf24-4952-aea0-31affedb7ff2
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T20:16:42.496Z'
---

## Overview

When processing issue and comment bodies, Gitea scanned the entire preceding text for action keywords such as "closes" or "fixes" once per Markdown link, giving processing time quadratic in the input size. An authenticated user able to submit issue or comment content could send a crafted body of about 1 MB that keeps a CPU core busy for several minutes while holding a database transaction open.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
