🛡️ CVE-2026-55984 — gitea.dev

🟢 CVSS 2.0 — Low ✅ No Known Exploit CWE-476 OSV
2.0
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service

Summary

The AddTime API handler continues execution after an error returned by GetUserByName().

When a repository administrator specifies a non-existent user name, an error response is generated but execution does not stop. Subsequent code dereferences a nil user pointer, resulting in a runtime panic.

Details

Affected endpoint:

```http

POST /api/v1/repos/{owner}/{repo}/issues/{index}/times

```

Affected file:

```text

routers/api/v1/repo/issue_tracked_time.go

```

Relevant code:

```go

user, err = user_model.GetUserByName(ctx, form.User)

if err != nil {

ctx.APIErrorInternal(err)

// missing return

}

```

Execution continues to:

```go

trackedTime, err := issues_model.AddTime(

ctx,

user,

issue,

form.Time,

created,

)

```

When GetUserByName() fails, user is nil.

The subsequent call dereferences the nil pointer and triggers a runtime panic.

Proof of Concept

Using a repository administrator account:

```http

POST /api/v1/repos/owner/repo/issues/1/times

Content-Type: application/json

{

"time": 3600,

"user_name": "nonexistent_user_xyz"

}

```

Result:

```text

HTTP 500

runtime error: invalid memory address or nil pointer dereference

```

The stack trace indicates execution reaches the AddTime code path with a nil user object.

Impact

An authenticated repository administrator can repeatedly trigger server-side panics through the affected endpoint.

Depending on deployment configuration and panic recovery behavior, this may result in request failures, stack trace disclosure, excessive log generation, or degraded service availability.

Suggested Fix

Add a return statement after the error response:

```go

user, err = user_model.GetUserByName(ctx, form.User)

if err != nil {

ctx.APIErrorInternal(err)

return

}

```

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is low, an attacker needs administrative privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality none, integrity none, availability low.

Weakness class

CVE-2026-55984 is classified as CWE-476: NULL Pointer Dereference. A pointer that can be null is used without a check, crashing the process.

Affected software

CVE-2026-55984 is recorded against 2 packages.

  • code.gitea.io/gitea
  • gitea.dev

Timeline and source

Published on 21 July 2026 and last revised on 27 July 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

github.com (Web)
github.com (Package)
github.com (Web)

Details

Severity LOW
CVSS Score 2.0
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
CWE CWE-476
Public Exploit ✅ No
Source OSV
Published 2026-07-21
Updated 2026-08-12
Modified 2026-07-27
Fix URL N/A

Affected Packages

Software From version Fixed in
code.gitea.io/gitea
gitea.dev

Similar Threats

Free Vulnerability Check

Is your site affected by CVE-2026-55984?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against CVE-2026-55984 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.