CVE-2026-56657: medium-severity vulnerability in Gitea Open Source Git Server
Gitea SSH Key Parser Denial of Service
Published
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.2epss 0.2%
exploitation probability
0.2%top 94% of all CVEs
observed exploitation
nono source reports it
Gitea SSH Key Parser Denial of Service
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
Gitea · Gitea Open Source Git ServerRelated CVEs — Gitea Open Source Git Server
In the same product, most dangerous first.
CVE-2024-6886CRITICALInproper Sanitation of field leading to stored XSSEPSS 33.0%CVE-2026-20896CRITICALGitea Docker image trusts spoofable reverse-proxy headers by defaultEPSS 2.8%CVE-2026-27771HIGHGitea Composer package source links use insufficient permission checksEPSS 1.4%CVE-2026-26292CRITICALGitea LFS mirror synchronization bypasses migration HTTP transport restrictionsEPSS 0.7%CVE-2026-27780CRITICALGitea pre-receive hook can miss branch-protection checks after scanner errorsEPSS 0.6%CVE-2026-26307HIGHGitea git grep search lacks a timeoutEPSS 0.6%