Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2026-52800High· 8.8Gogs Vulnerable to CSRF Leading to Organization Owner Takeover
CVE-2026-52801High· 8.1Gogs has the ability to import local repositories via Mirror Settings
CVE-2026-52802Medium· 5.4Gogs has an Open Redirect via redirect_to
CVE-2026-52804MediumGogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation
CVE-2026-52805High· 8.7Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft
CVE-2026-52806Critical· 9.9PoCGogs vulnerable to RCE via git rebase --exec argument injection in pull request merge
CVE-2026-52807HighGogs has DOM-based XSS via Milestone Name on New Issue Page
CVE-2026-52808High· 7.1Gogs's write-level collaborators can mutate admin-only repository settings via API
CVE-2026-52809Medium· 6.8Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES
CVE-2026-52810HighPoCGogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion
CVE-2026-52811CriticalGogs: UploadRepoFiles writes outside repo working tree via committed parent sym
CVE-2026-52812HighGogs: LFS dedupe path leaks private repo content across tenants
CVE-2026-52813Critical· 10.0PoCGogs has Path Traversal in organization name that results in RCE through Git hooks
CVE-2026-52814MediumGogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion)
CVE-2026-52815MediumPoCGogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API
CVE-2026-52816MediumGogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS
CVE-2025-64719Medium· 4.9Gogs has a Denial of Service in repository/wiki file listing web pages
CVE-2026-25119HighGogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers
CVE-2026-47267MediumGogs has SSRF in webhook deliveries
CVE-2026-52796Low· 3.5Gogs has DoS in rendering issue index pattern
CVE-2026-52798High· 8.9Gogs has Stored XSS in `.ipynb` Preview
CVE-2026-52799High· 7.5Gogs Missing Authorization in Attachment Download
GHSA-6vxv-wg6j-5qwpHighGogs: XSS in .ipynb files renderer due to outdated notebookjs
CVE-2026-52797High· 8.5Gogs: Overwriting critical files results in a denial of service
CVE-2021-32546CriticalOS Command Injection in gogs
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.