Junglewise Threat Intelligence

CVE-2026-58369: Woodpecker CI NULL pointer dereference in organization lookup API

CVE-2026-58369 · Severity: medium · CVSS 5.3 · Published 2026-06-30

Technologies: Woodpecker CI. Vendors: Woodpecker CI.

Executive brief

Woodpecker, a continuous integration (CI) platform, contains a flaw in how it handles certain public web requests. An unauthenticated attacker can send repeated requests to a specific web address to cause the server to crash internally and generate large amounts of error data. While the server automatically restarts, this 'log flooding' can fill up server storage, increase operational costs, and hide evidence of other malicious activities.

Technical details

Woodpecker CI versions prior to 3.15.0 register the '/api/orgs/lookup/*org_full_name' endpoint without authentication middleware. The 'LookupOrg' handler unconditionally dereferences the session user object (specifically 'user.ForgeID' via 'ForgeFromUser') to determine which forge to query. Because unauthenticated requests return a nil session user, this results in a NULL pointer dereference. While the 'gin' recovery middleware prevents a total service crash by recovering from the panic and returning an HTTP 500 error, each request generates a multi-line stack trace (approximately 37 lines). An unauthenticated remote attacker can exploit this to flood logs, exhaust disk space, and obscure legitimate audit trails. This issue was addressed in version 3.15.0.

Affected products

  • Woodpecker CI Woodpecker before 3.15.0

Timeline

  • 2026-05-27: patched: Fix merged into main branch
  • 2026-05-28: advisory: Version 3.15.0 released
  • 2026-06-30: disclosed: CVE published

References