PT-2026-107169 · Gitea · Gitea
CVE-2026-103059
·
Published
2026-10-06
·
Updated
2026-10-06
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
When Gitea's built-in SSH server is enabled (
START SSH SERVER = true), the presented public key was looked up with an SQL LIKE comparison of its encoded content, which is case-insensitive on some databases, including the default SQLite. An attacker who can construct a case variant of another user's registered RSA public key for which they can derive the private key could have that key matched to the victim's account and authenticate over SSH as that user. Keys are now looked up by fingerprint. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gitea