PT-2026-107169 · Gitea · Gitea

CVE-2026-103059

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
When Gitea's built-in SSH server is enabled (START SSH SERVER = true), the presented public key was looked up with an SQL LIKE comparison of its encoded content, which is case-insensitive on some databases, including the default SQLite. An attacker who can construct a case variant of another user's registered RSA public key for which they can derive the private key could have that key matched to the victim's account and authenticate over SSH as that user. Keys are now looked up by fingerprint.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-103059

Affected Products

Gitea