Null Pointer Dereference Vulnerability in Gitea Product by Gitea
CVE-2026-55984

Currently unrated

Key Information:

Vendor

Gitea

Vendor
CVE Published:
13 August 2026

What is CVE-2026-55984?

A null pointer dereference vulnerability exists in the AddTime API of Gitea, leading to potential authenticated denial of service conditions. This flaw can be exploited by authenticated users, allowing them to disrupt service availability by triggering specific API calls. The issue has been addressed in Gitea v1.27.0, and users are encouraged to update to maintain optimal security and functionality. For further details, consult the GitHub Security Advisory and the associated release notes.

Affected Version(s)

Gitea Open Source Git Server 0 <= 1.26.4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

martijnperdaan52
.