Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

gogs — Vulnerabilities & Security Advisories 47

All 47 CVE vulnerabilities found in gogs, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for Gogs, a self-hosted Git service, focusing on common software weaknesses and security flaws. It collects reported security vulnerabilities affecting the Gogs platform, covering historical data from its early development phases through recent updates up to the current year. Here, users can track vendor-specific advisories as they are published, understand the nature and impact of specific weakness classes within the context of a lightweight Git solution, and look up the complete vulnerability history of the product to assess risk over time. Gogs, being a go-based alternative to GitLab, has faced various security challenges ranging from authentication bypasses to arbitrary file read vulnerabilities. This collection aims to provide transparency for system administrators and security researchers who rely on Gogs for private version control. By consolidating these records, the page serves as a central reference point for evaluating the security posture of deployed instances. Users can identify patterns in reported defects, such as privilege escalation issues or input validation failures, which helps in prioritizing patching efforts and hardening configurations. The data includes details on affected versions and the severity of each flaw, enabling informed decision-making regarding upgrades and mitigation strategies. This resource is particularly valuable for teams managing on-premises infrastructure where staying abreast of niche software vulnerabilities is critical for maintaining overall system integrity and data security.

Vendor: gogs

CVE IDTitleCVSSSeverityPublished
CVE-2026-52797 Gogs: Overwriting critical files results in a denial of service CWE-22 8.5 High2026-06-24
CVE-2026-52813 Gogs: Path Traversal in organization name results in RCE through Git hooks CWE-23 10.0 Critical2026-06-24
CVE-2026-52812 Gogs: LFS dedupe path leaks private repo content across tenants CWE-345--2026-06-24
CVE-2026-52811 Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym CWE-22--2026-06-24
CVE-2026-52810 Gogs: Write to readonly repositories using receive-pack + service=git-upload-pack confusion CWE-284--2026-06-24
CVE-2026-52809 Gogs: Password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES CWE-324 6.8 Medium2026-06-24
CVE-2026-52808 Gogs: Write-level collaborators can mutate admin-only repository settings via API CWE-863 7.1 High2026-06-24
CVE-2026-52816 Gogs: Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS CWE-80--2026-06-24
CVE-2026-52807 Gogs: DOM-based XSS via Milestone Name on New Issue Page CWE-79--2026-06-24
CVE-2026-52805 Gogs: Migration Redirect Bypass Leads to Internal Repository Theft CWE-918 8.7 High2026-06-24
CVE-2026-52806 Gogs: RCE via git rebase --exec argument injection in pull request merge CWE-77 9.9 Critical2026-06-24
CVE-2026-52804 Gogs: Privilege Escalation via Collaboration Access Mode Validation CWE-193--2026-06-24
CVE-2026-52799 Gogs: Missing Authorization in Attachment Download CWE-639 7.5 High2026-06-24
CVE-2026-52801 Gogs: Ability to import local repositories via Mirror Settings CWE-20 8.1 High2026-06-24
CVE-2026-52800 Gogs: CSRF Leading to Organization Owner Takeover CWE-352 8.8 High2026-06-24
CVE-2026-52802 Gogs: Open Redirect via redirect_to in Gogs CWE-601 5.4 Medium2026-06-24
CVE-2026-52814 Gogs: Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) CWE-400--2026-06-24
CVE-2026-52798 Gogs: Stored XSS in `.ipynb` Preview CWE-79 8.9 High2026-06-24
CVE-2026-52796 Gogs: DoS in rendering issue index pattern CWE-1336 3.5 Low2026-06-24
CVE-2026-47267 Gogs: SSRF in webhook deliveries CWE-918 8.3 High2026-06-24
CVE-2026-25119 Gogs: Authentication Bypass via Unvalidated Reverse Proxy Headers CWE-290--2026-06-24
CVE-2026-52795 Gogs: Authorization Bypass in Watch API allows any user to monitor private repository activity CWE-863 4.3 Medium2026-06-24
CVE-2025-64719 Gogs: Denial of Service in repository/wiki file listing web pages CWE-20 4.9 Medium2026-06-24
CVE-2026-52815 Gogs: Unauthenticated Organization Teams Information Disclosure via API CWE-200--2026-06-24
CVE-2026-26276 Gogs: DOM-based XSS via milestone selection CWE-79 7.3 High2026-03-05
CVE-2026-26196 Gogs: Access tokens get exposed through URL params in API requests CWE-598 5.3 -2026-03-05
CVE-2026-26195 Gogs: Stored XSS in branch and wiki views through author and committer names CWE-79 5.4 -2026-03-05
CVE-2026-26194 Gogs: Release tag option injection in release deletion CWE-88 7.1 -2026-03-05
CVE-2026-25921 Gogs: Cross-repository LFS object overwrite via missing content hash verification CWE-345 9.3 Critical2026-03-05
CVE-2026-26022 Gogs: Stored XSS via data URI in issue comments CWE-79 8.7 High2026-03-05

All 47 known CVE vulnerabilities affecting gogs with full Chinese analysis, references, and POCs where available.