Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
### Summary The AddTime API handler continues execution after an error returned by `GetUserByName()`. When a repository administrator specifies a non-existent user name, an error response is generated but execution does not stop. Subsequent code dereferences a nil user pointer, resulting in a runtime panic. ### Details Affected endpoint: ```http POST /api/v1/repos/{owner}/{repo}/issues/{index}/times ``` Affected file: ```text routers/api/v1/repo/issue_tracked_time.go ``` Relevant code: ```go user, err = user_model.GetUserByName(ctx, form.User) if err != nil { ctx.APIErrorInternal(err) // missing return } ``` Execution continues to: ```go trackedTime, err := issues_model.AddTime( ctx, user, issue, form.Time, created, ) ``` When `GetUserByName()` fails, `user` is nil. The subsequent call dereferences the nil pointer and triggers a runtime panic. ### Proof of Concept Using a repository administrator account: ```http POST /api/v1/repos/owner/repo/issues/1/times Content-Type: application/json { "time": 3600, "user_name": "nonexistent_user_xyz" } ``` Result: ```text HTTP 500 runtime error: invalid memory address or nil pointer dereference ``` The stack trace indicates execution reaches the AddTime code path with a nil user object. ### Impact An authenticated repository administrator can repeatedly trigger server-side panics through the affected endpoint. Depending on deployment configuration and panic recovery behavior, this may result in request failures, stack trace disclosure, excessive log generation, or degraded service availability. ### Suggested Fix Add a return statement after the error response: ```go user, err = user_model.GetUserByName(ctx, form.User) if err != nil { ctx.APIErrorInternal(err) return } ```
02 / AFFECTED SOFTWARE
Affected packages
38 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
### Summary The AddTime API handler continues execution after an error returned by `GetUserByName()`. When a repository administrator specifies a non-existent user name, an error response is generated but execution does not stop. Subsequent code dereferences a nil user pointer, resulting in a runtime panic. ### Details Affected endpoint: ```http POST /api/v1/repos/{owner}/{repo}/issues/{index}/times ``` Affected file: ```text routers/api/v1/repo/issue_tracked_time.go ``` Relevant code: ```go user, err = user_model.GetUserByName(ctx, form.User) if err != nil { ctx.APIErrorInternal(err) // missing return } ``` Execution continues to: ```go trackedTime, err := issues_model.AddTime( ctx, user, issue, form.Time, created, ) ``` When `GetUserByName()` fails, `user` is nil. The subsequent call dereferences the nil pointer and triggers a runtime panic. ### Proof of Concept Using a repository administrator account: ```http POST /api/v1/repos/owner/repo/issues/1/times Content-Type: application/json { "time": 3600, "user_name": "nonexistent_user_xyz" } ``` Result: ```text HTTP 500 runtime error: invalid memory address or nil pointer dereference ``` The stack trace indicates execution reaches the AddTime code path with a nil user object. ### Impact An authenticated repository administrator can repeatedly trigger server-side panics through the affected endpoint. Depending on deployment configuration and panic recovery behavior, this may result in request failures, stack trace disclosure, excessive log generation, or degraded service availability. ### Suggested Fix Add a return statement after the error response: ```go user, err = user_model.GetUserByName(ctx, form.User) if err != nil { ctx.APIErrorInternal(err) return } ```
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev
05 / REFERENCES
Further evidence
- https://blog.gitea.com/gitea-1.27.0-is-released/
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55984.json
- https://github.com/go-gitea/gitea/releases/tag/v1.27.0
- https://github.com/go-gitea/gitea/security/advisories/GHSA-m932-crvm-gcp5
- https://nvd.nist.gov/vuln/detail/CVE-2026-55984
- https://github.com/go-gitea/gitea