CVE-2026-55984
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
Summary
### Summary The AddTime API handler continues execution after an error returned by `GetUserByName()`. When a repository administrator specifies a non-existent user name, an error response is generated but execution does not stop. Subsequent code dereferences a nil user pointer, resulting in a runtime panic. ### Details Affected endpoint: ```http POST /api/v1/repos/{owner}/{repo}/issues/{index}/times ``` Affected file: ```text routers/api/v1/repo/issue_tracked_time.go ``` Relevant code: ```go user, err = user_model.GetUserByName(ctx, form.User) if err != nil { ctx.APIErrorInternal(err) // missing return } ``` Execution continues to: ```go trackedTime, err := issues_model.AddTime( ctx, user, issue, form.Time, created, ) ``` When `GetUserByName()` fails, `user` is nil. The subsequent call dereferences the nil pointer and triggers a runtime panic. ### Proof of Concept Using a repository administrator account: ```http POST /api/v1/repos/owner/repo/issues/1/times Content-Type: application/json { "time": 3600, "user_name": "nonexistent_user_xyz" } ``` Result: ```text HTTP 500 runtime error: invalid memory address or nil pointer dereference ``` The stack trace indicates execution reaches the AddTime code path with a nil user object. ### Impact An authenticated repository administrator can repeatedly trigger server-side panics through the affected endpoint. Depending on deployment configuration and panic recovery behavior, this may result in request failures, stack trace disclosure, excessive log generation, or degraded service availability. ### Suggested Fix Add a return statement after the error response: ```go user, err = user_model.GetUserByName(ctx, form.User) if err != nil { ctx.APIErrorInternal(err) return } ```
Affected packages
| Ecosystem | Package | Affected versions | Fixed versions |
|---|---|---|---|
| Go | code.gitea.io/gitea | — | 1.27.0 |
Remediation: Upgrade to 1.27.0 or later.
References
Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.
CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.