Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

gogs — Vulnerabilities & Security Advisories 47

All 47 CVE vulnerabilities found in gogs, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities affecting the Gogs product, focusing on its software weaknesses and associated advisories. It collects known issues spanning recent years, covering both high-severity flaws and lower-risk configuration problems. Readers can track the vendor's advisory history, understand specific weakness classes, and review the product's cumulative vulnerability landscape without parsing individual CVE records separately.

Vendor: gogs

CVE ID Title CVSS Severity Published
CVE-2026-52797 Gogs: Overwriting critical files results in a denial of service CWE-22 8.5 High 2026-06-24
CVE-2026-52813 Gogs: Path Traversal in organization name results in RCE through Git hooks CWE-23 10.0 Critical 2026-06-24
CVE-2026-52812 Gogs: LFS dedupe path leaks private repo content across tenants CWE-345 - - 2026-06-24
CVE-2026-52811 Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym CWE-22 - - 2026-06-24
CVE-2026-52810 Gogs: Write to readonly repositories using receive-pack + service=git-upload-pack confusion CWE-284 - - 2026-06-24
CVE-2026-52809 Gogs: Password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES CWE-324 6.8 Medium 2026-06-24
CVE-2026-52808 Gogs: Write-level collaborators can mutate admin-only repository settings via API CWE-863 7.1 High 2026-06-24
CVE-2026-52816 Gogs: Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS CWE-80 - - 2026-06-24
CVE-2026-52807 Gogs: DOM-based XSS via Milestone Name on New Issue Page CWE-79 - - 2026-06-24
CVE-2026-52805 Gogs: Migration Redirect Bypass Leads to Internal Repository Theft CWE-918 8.7 High 2026-06-24
CVE-2026-52806 Gogs: RCE via git rebase --exec argument injection in pull request merge CWE-77 9.9 Critical 2026-06-24
CVE-2026-52804 Gogs: Privilege Escalation via Collaboration Access Mode Validation CWE-193 - - 2026-06-24
CVE-2026-52799 Gogs: Missing Authorization in Attachment Download CWE-639 7.5 High 2026-06-24
CVE-2026-52801 Gogs: Ability to import local repositories via Mirror Settings CWE-20 8.1 High 2026-06-24
CVE-2026-52800 Gogs: CSRF Leading to Organization Owner Takeover CWE-352 8.8 High 2026-06-24
CVE-2026-52802 Gogs: Open Redirect via redirect_to in Gogs CWE-601 5.4 Medium 2026-06-24
CVE-2026-52814 Gogs: Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) CWE-400 - - 2026-06-24
CVE-2026-52798 Gogs: Stored XSS in `.ipynb` Preview CWE-79 8.9 High 2026-06-24
CVE-2026-52796 Gogs: DoS in rendering issue index pattern CWE-1336 3.5 Low 2026-06-24
CVE-2026-47267 Gogs: SSRF in webhook deliveries CWE-918 8.3 High 2026-06-24
CVE-2026-25119 Gogs: Authentication Bypass via Unvalidated Reverse Proxy Headers CWE-290 - - 2026-06-24
CVE-2026-52795 Gogs: Authorization Bypass in Watch API allows any user to monitor private repository activity CWE-863 4.3 Medium 2026-06-24
CVE-2025-64719 Gogs: Denial of Service in repository/wiki file listing web pages CWE-20 4.9 Medium 2026-06-24
CVE-2026-52815 Gogs: Unauthenticated Organization Teams Information Disclosure via API CWE-200 - - 2026-06-24
CVE-2026-26276 Gogs: DOM-based XSS via milestone selection CWE-79 7.3 High 2026-03-05
CVE-2026-26196 Gogs: Access tokens get exposed through URL params in API requests CWE-598 5.3 - 2026-03-05
CVE-2026-26195 Gogs: Stored XSS in branch and wiki views through author and committer names CWE-79 5.4 - 2026-03-05
CVE-2026-26194 Gogs: Release tag option injection in release deletion CWE-88 7.1 - 2026-03-05
CVE-2026-25921 Gogs: Cross-repository LFS object overwrite via missing content hash verification CWE-345 9.3 Critical 2026-03-05
CVE-2026-26022 Gogs: Stored XSS via data URI in issue comments CWE-79 8.7 High 2026-03-05

All 47 known CVE vulnerabilities affecting gogs with full Chinese analysis, references, and POCs where available.