AI analysis
When Gitea's built-in SSH server is enabled (START_SSH_SERVER=true), a presented public key was matched with an SQL LIKE comparison of its encoded content, which is case-insensitive on some databases, including the default SQLite. An attacker who can build a case variant of another user's registered RSA public key and derive the corresponding private key can have that key matched to the victim's account and authenticate over SSH as that user. The result is unauthorized access to the victim's repositories and account privileges, with high confidentiality and integrity impact and no availability impact (CVSS 9.1). Only deployments that turn on the built-in SSH server and store keys in a case-insensitive database are exposed; keys are now looked up by fingerprint. No public proof-of-concept is known, and the issue is not listed in CISA KEV.
What to do: Upgrade to a Gitea release that looks up SSH public keys by fingerprint instead of SQL LIKE. Until you can upgrade, set START_SSH_SERVER=false and use the operating-system SSH daemon, and review SSH logs for authentications that do not match a user's registered key material.
Estimated exposure
moderateon the order of 1,000–10,000 instances with the vulnerable built-in SSH configuration — Gitea is a widely used self-hosted Git service, with public internet scans typically showing on the order of tens of thousands of reachable instances; only the subset that enables the built-in SSH server and uses a case-insensitive…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
When Gitea's built-in SSH server is enabled (`START_SSH_SERVER = true`), the presented public key was looked up with an SQL `LIKE` comparison of its encoded content, which is case-insensitive on some databases, including the default SQLite. An attacker who can construct a case variant of another user's registered RSA public key for which they can derive the private key could have that key matched to the victim's account and authenticate over SSH as that user. Keys are now looked up by fingerprint.