Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Oct 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-287 |
Wed, 07 Oct 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-305 | |
| Metrics |
cvssV3_1
|
Tue, 06 Oct 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gitea
Gitea gitea |
|
| Vendors & Products |
Gitea
Gitea gitea |
Tue, 06 Oct 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-287 |
Tue, 06 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When Gitea's built-in SSH server is enabled (`START_SSH_SERVER = true`), the presented public key was looked up with an SQL `LIKE` comparison of its encoded content, which is case-insensitive on some databases, including the default SQLite. An attacker who can construct a case variant of another user's registered RSA public key for which they can derive the private key could have that key matched to the victim's account and authenticate over SSH as that user. Keys are now looked up by fingerprint. | |
| Title | Gitea built-in SSH server authentication bypass through key case folding | |
| References |
|
Status: PUBLISHED
Assigner: Gitea
Published:
Updated: 2026-10-07T14:17:20.596Z
Reserved: 2026-10-04T21:57:35.559Z
Link: CVE-2026-103059
Updated: 2026-10-07T14:16:38.441Z
Status : Awaiting Analysis
Published: 2026-10-06T20:17:14.377
Modified: 2026-10-07T15:16:56.737
Link: CVE-2026-103059
No data.
OpenCVE Enrichment
Updated: 2026-10-07T19:00:16Z