Executive brief
Gitea is an open-source forge software package for hosting software development version control using Git. A vulnerability in how the system processes SSH keys allows an authenticated user to crash the server by uploading a specially crafted, large key file. This can lead to a total service outage, preventing teams from accessing their code repositories and disrupting development operations.
Technical details
The vulnerability exists in the `parseKeyString` function within Gitea's SSH key normalization logic. When processing RFC 4716 (SSH2) format keys, the application splits the input on newlines and accumulates the key body using the `+=` operator in Go. Because Go strings are immutable, this results in an O(N²) complexity for both time and memory allocations as the entire string is copied for every line processed. An authenticated attacker can submit a key with hundreds of thousands of short lines to trigger quadratic resource consumption before any size validation or cryptographic checks occur. This leads to rapid CPU exhaustion and Out-of-Memory (OOM) conditions. The issue is fixed in version 1.27.0.
Affected products
- Gitea Gitea < 1.27.0
Timeline
- 2026-07-13: disclosed: Initial disclosure on GitHub Advisory Database
- 2026-07-21: advisory: Advisory updated and published