GHSA-m932-crvm-gcp5
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
Quick fix
GHSA-m932-crvm-gcp5 — code.gitea.io/gitea: upgrade to the fixed version with the command below.
go get code.gitea.io/gitea@v1.27.0 Details
### Summary
The AddTime API handler continues execution after an error returned by `GetUserByName()`.
When a repository administrator specifies a non-existent user name, an error response is generated but execution does not stop. Subsequent code dereferences a nil user pointer, resulting in a runtime panic.
### Details
Affected endpoint:
```http POST /api/v1/repos/{owner}/{repo}/issues/{index}/times ```
Affected file:
```text routers/api/v1/repo/issue_tracked_time.go ```
Relevant code:
```go user, err = user_model.GetUserByName(ctx, form.User) if err != nil { ctx.APIErrorInternal(err) // missing return } ```
Execution continues to:
```go trackedTime, err := issues_model.AddTime( ctx, user, issue, form.Time, created, ) ```
When `GetUserByName()` fails, `user` is nil.
The subsequent call dereferences the nil pointer and triggers a runtime panic.
### Proof of Concept
Using a repository administrator account:
```http POST /api/v1/repos/owner/repo/issues/1/times Content-Type: application/json
{ "time": 3600, "user_name": "nonexistent_user_xyz" } ```
Result:
```text HTTP 500 runtime error: invalid memory address or nil pointer dereference ```
The stack trace indicates execution reaches the AddTime code path with a nil user object.
### Impact
An authenticated repository administrator can repeatedly trigger server-side panics through the affected endpoint.
Depending on deployment configuration and panic recovery behavior, this may result in request failures, stack trace disclosure, excessive log generation, or degraded service availability.
### Suggested Fix
Add a return statement after the error response:
```go user, err = user_model.GetUserByName(ctx, form.User) if err != nil { ctx.APIErrorInternal(err) return } ```
Are you affected?
Enter the version of the package you're using.