CVE-2026-103059: Gitea built-in SSH server authentication bypass through key case folding

Published Oct 6, 2026
·
Updated

When Gitea's built-in SSH server is enabled (STARTSSHSERVER = true), the presented public key was looked up with an SQL LIKE comparison of its encoded content, which is case-insensitive on some databases, including the default SQLite. An attacker who can construct a case variant of another user's registered RSA public key for which they can derive the private key could have that key matched to the victim's account and authenticate over SSH as that user. Keys are now looked up by fingerprint.

Affected Software

1 affected component
Gitea Gitea

Event History

Oct 6, 2026
CVE Published
via MITRE·07:22 PM
Data Sourced
via MITRE·07:22 PM
Description
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

Deployments using Gitea's built-in SSH server with START_SSH_SERVER set to true are affected. The issue is particularly relevant on databases whose SQL LIKE comparison is case-insensitive, including the default SQLite.

2

What must an attacker be able to do to authenticate as another user?

The attacker must construct a case variant of a victim's registered RSA public key and be able to derive the corresponding private key. If the case-insensitive lookup matches that variant, SSH authentication can be performed as the victim account.

3

How was the issue addressed?

Public keys are now looked up by fingerprint rather than using an SQL LIKE comparison of encoded key content.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203