Threats Tagged 'cve-2026-58436'
View all threats tagged with 'cve-2026-58436'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-58436'
Click on any threat for detailed analysis and mitigation recommendations
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests (CVE-2026-58436)CVE-2026-58436 0 Gitea contains a denial-of-service vulnerability in its Locale middleware that processes the Accept-Language HTTP header on every unauthenticated request. The vulnerability arises because the middleware calls golang.org/x/text/language.ParseAcceptLanguage on unfiltered Accept-Language headers, which can contain a large number of underscore characters. The parser has quadratic-time complexity on such inputs, allowing attackers to cause high CPU usage and degrade service availability. This affects all Gitea versions prior to 1.27.0 that do not impose their own size limits on the Accept-Language header. Join the discussion | GCVE Database | 07/21/2026, 21:15:47 UTC Added: 07/22/2026, 00:11:28 UTC |
Showing 1 to 1 of 1 result