Executive brief
Woodpecker, a continuous integration (CI) platform, contains a flaw in how it handles certain public web requests. An unauthenticated attacker can send repeated requests to a specific web address to cause the server to crash internally and generate large amounts of error data. While the server automatically restarts, this 'log flooding' can fill up server storage, increase operational costs, and hide evidence of other malicious activities.
Technical details
Woodpecker CI versions prior to 3.15.0 register the '/api/orgs/lookup/*org_full_name' endpoint without authentication middleware. The 'LookupOrg' handler unconditionally dereferences the session user object (specifically 'user.ForgeID' via 'ForgeFromUser') to determine which forge to query. Because unauthenticated requests return a nil session user, this results in a NULL pointer dereference. While the 'gin' recovery middleware prevents a total service crash by recovering from the panic and returning an HTTP 500 error, each request generates a multi-line stack trace (approximately 37 lines). An unauthenticated remote attacker can exploit this to flood logs, exhaust disk space, and obscure legitimate audit trails. This issue was addressed in version 3.15.0.
Affected products
- Woodpecker CI Woodpecker before 3.15.0
Timeline
- 2026-05-27: patched: Fix merged into main branch
- 2026-05-28: advisory: Version 3.15.0 released
- 2026-06-30: disclosed: CVE published
References
- https://github.com/woodpecker-ci/woodpecker/commit/1fbacac3a43b75b6e5a0a40a4f720a0017c62010
- https://github.com/woodpecker-ci/woodpecker/pull/6652
- https://github.com/woodpecker-ci/woodpecker/releases/tag/v3.15.0
- https://www.vulncheck.com/advisories/woodpecker-unauthenticated-null-pointer-dereference-in-api-orgs-lookup-enables-log-flooding-denial-of-service