Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

gogs — Vulnerabilities & Security Advisories 57

Browse all 57 CVE security advisories affecting gogs. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Gogs is a lightweight, self-hosted Git service written in Go, primarily used by organizations requiring private repository management without the complexity of larger alternatives. Despite its simplicity, the platform has accumulated thirty-three recorded Common Vulnerabilities and Exposures, reflecting persistent security challenges in its codebase. Historically, these flaws predominantly involve remote code execution, cross-site scripting, and privilege escalation, often stemming from improper input validation or authentication bypasses. While Gogs emphasizes ease of deployment and low resource consumption, its smaller development team compared to enterprise competitors has occasionally delayed critical patches. Recent incidents highlight risks associated with exposed administrative interfaces and insecure default configurations. Users must prioritize regular updates and strict access controls to mitigate these known weaknesses, ensuring that the convenience of self-hosting does not compromise infrastructure integrity against increasingly sophisticated threat actors targeting version control systems.

Top products by gogs: gogs gogs/gogs
CVE ID Title CVSS Severity Published
CVE-2026-25229 Gogs Authorization Bypass Allows Cross-Repository Label Modification — gogs CWE-284 4.3 - 2026-02-19
CVE-2026-25242 Gogs allows unauthenticated file uploads — gogs CWE-862 9.8 - 2026-02-19
CVE-2026-25232 Gogs has a Protected Branch Deletion Bypass in Web Interface — gogs CWE-863 8.8 - 2026-02-19
CVE-2026-25120 Gogs Allows Cross-Repository Comment Deletion via DeleteComment — gogs CWE-639 4.9 - 2026-02-19
CVE-2026-24135 Gogs vulnerable to arbitrary file deletion via path traversal in wiki page update — gogs CWE-22 8.1AI High AI 2026-02-06
CVE-2026-23633 Gogs has arbitrary file read/write via path traversal in Git hook editing — gogs CWE-22 6.5 Medium 2026-02-06
CVE-2026-23632 Gogs user can update repository content with read-only permission — gogs CWE-862 6.5 Medium 2026-02-06
CVE-2026-22592 Gogs is Vulnerable to Denial of Service — gogs CWE-862 6.5 Medium 2026-02-06
CVE-2025-64175 Gogs Vulnerable to 2FA Bypass via Recovery Code — gogs CWE-287 8.2AI High AI 2026-02-06
CVE-2025-64111 Gogs's update .git/config file allows remote command execution — gogs CWE-78 8.8AI High AI 2026-02-06
CVE-2025-8110 File overwrite in file update API in Gogs — Gogs CWE-22 7.8AI High AI 2025-12-10
CVE-2025-47943 Gogs stored XSS in PDF renderer — gogs CWE-79 6.3 Medium 2025-06-24
CVE-2024-56731 Gogs deletion of internal files allows remote command execution — gogs CWE-552 10.0 Critical 2025-06-24
CVE-2024-55947 Gogs has a Path Traversal in file update API — gogs CWE-22 8.8 - 2024-12-23
CVE-2024-54148 Gogs has a Path Traversal in file editing UI — gogs CWE-61 8.8 - 2024-12-23
CVE-2022-1884 Remote Command Execution in gogs/gogs — gogs/gogs CWE-78 8.1AI High AI 2024-11-15
CVE-2022-2024 OS Command Injection in gogs/gogs — gogs/gogs CWE-78 9.8 - 2023-02-25
CVE-2022-32174 Gogs - XSS — gogs CWE-79 7.6 - 2022-10-11
CVE-2022-1986 OS Command Injection in gogs/gogs — gogs/gogs CWE-78 9.8 - 2022-06-09
CVE-2022-31038 XSS vulnerability in repository issue list in Gogs — gogs CWE-79 5.4 Medium 2022-06-08
CVE-2022-1993 Path Traversal in gogs/gogs — gogs/gogs CWE-22 7.5 - 2022-06-08
CVE-2022-1992 Path Traversal in gogs/gogs — gogs/gogs CWE-22 7.5 - 2022-06-08
CVE-2022-1285 Server-Side Request Forgery (SSRF) in gogs/gogs — gogs/gogs CWE-918 8.2 - 2022-06-01
CVE-2022-1464 Stored xss bug in gogs/gogs — gogs/gogs CWE-79 5.4 - 2022-05-05
CVE-2022-0415 Remote Command Execution in uploading repository file in gogs/gogs — gogs/gogs CWE-20 8.8 - 2022-03-21
CVE-2022-0870 Server-Side Request Forgery (SSRF) in gogs/gogs — gogs/gogs CWE-918 8.2 - 2022-03-11
CVE-2022-0871 Missing Authorization in gogs/gogs — gogs/gogs CWE-862 7.5 - 2022-03-11

This page lists every published CVE security advisory associated with gogs. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.