VDB
KO
LOW 2.7

GHSA-m932-crvm-gcp5

Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service

Quick fix

GHSA-m932-crvm-gcp5 — code.gitea.io/gitea: upgrade to the fixed version with the command below.

go get code.gitea.io/gitea@v1.27.0

Details

### Summary

The AddTime API handler continues execution after an error returned by `GetUserByName()`.

When a repository administrator specifies a non-existent user name, an error response is generated but execution does not stop. Subsequent code dereferences a nil user pointer, resulting in a runtime panic.

### Details

Affected endpoint:

```http POST /api/v1/repos/{owner}/{repo}/issues/{index}/times ```

Affected file:

```text routers/api/v1/repo/issue_tracked_time.go ```

Relevant code:

```go user, err = user_model.GetUserByName(ctx, form.User) if err != nil { ctx.APIErrorInternal(err) // missing return } ```

Execution continues to:

```go trackedTime, err := issues_model.AddTime( ctx, user, issue, form.Time, created, ) ```

When `GetUserByName()` fails, `user` is nil.

The subsequent call dereferences the nil pointer and triggers a runtime panic.

### Proof of Concept

Using a repository administrator account:

```http POST /api/v1/repos/owner/repo/issues/1/times Content-Type: application/json

{ "time": 3600, "user_name": "nonexistent_user_xyz" } ```

Result:

```text HTTP 500 runtime error: invalid memory address or nil pointer dereference ```

The stack trace indicates execution reaches the AddTime code path with a nil user object.

### Impact

An authenticated repository administrator can repeatedly trigger server-side panics through the affected endpoint.

Depending on deployment configuration and panic recovery behavior, this may result in request failures, stack trace disclosure, excessive log generation, or degraded service availability.

### Suggested Fix

Add a return statement after the error response:

```go user, err = user_model.GetUserByName(ctx, form.User) if err != nil { ctx.APIErrorInternal(err) return } ```

Are you affected?

Enter the version of the package you're using.

Affected packages

Go / code.gitea.io/gitea
Introduced in: 0 Fixed in: 1.27.0
Fix go get code.gitea.io/gitea@v1.27.0

References