gogs.io/gogs vulnerabilities
CVEs whose affected-version data names the gogs.io/gogs package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
25 CVEsRSS
CVE-2026-52800High· 8.8Gogs Vulnerable to CSRF Leading to Organization Owner Takeover
Gogs Vulnerable to CSRF Leading to Organization Owner Takeover
CVE-2026-52801High· 8.1Gogs has the ability to import local repositories via Mirror Settings
Gogs has the ability to import local repositories via Mirror Settings
CVE-2026-52802Medium· 5.4Gogs has an Open Redirect via redirect_to
Gogs has an Open Redirect via redirect_to
CVE-2026-52804MediumGogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation
Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation
CVE-2026-52805High· 8.7Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft
Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft
CVE-2026-52806Critical· 9.9PoCGogs vulnerable to RCE via git rebase --exec argument injection in pull request merge
Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge
CVE-2026-52807HighGogs has DOM-based XSS via Milestone Name on New Issue Page
Gogs has DOM-based XSS via Milestone Name on New Issue Page
CVE-2026-52808High· 7.1Gogs's write-level collaborators can mutate admin-only repository settings via API
Gogs's write-level collaborators can mutate admin-only repository settings via API
CVE-2026-52809Medium· 6.8Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES
Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES
CVE-2026-52810HighPoCGogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion
Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion
CVE-2026-52811CriticalGogs: UploadRepoFiles writes outside repo working tree via committed parent sym
Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym
CVE-2026-52812HighGogs: LFS dedupe path leaks private repo content across tenants
Gogs: LFS dedupe path leaks private repo content across tenants
CVE-2026-52813Critical· 10.0PoCGogs has Path Traversal in organization name that results in RCE through Git hooks
Gogs has Path Traversal in organization name that results in RCE through Git hooks
CVE-2026-52814MediumGogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion)
Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion)
CVE-2026-52815MediumPoCGogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API
Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API
CVE-2026-52816MediumGogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS
Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS
CVE-2025-64719Medium· 4.9Gogs has a Denial of Service in repository/wiki file listing web pages
Gogs has a Denial of Service in repository/wiki file listing web pages
CVE-2026-25119HighGogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers
Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers
CVE-2026-47267MediumGogs has SSRF in webhook deliveries
Gogs has SSRF in webhook deliveries
CVE-2026-52796Low· 3.5Gogs has DoS in rendering issue index pattern
Gogs has DoS in rendering issue index pattern
CVE-2026-52798High· 8.9Gogs has Stored XSS in `.ipynb` Preview
Gogs has Stored XSS in `.ipynb` Preview
CVE-2026-52799High· 7.5Gogs Missing Authorization in Attachment Download
Gogs Missing Authorization in Attachment Download
GHSA-6vxv-wg6j-5qwpHighGogs: XSS in .ipynb files renderer due to outdated notebookjs
Gogs: XSS in .ipynb files renderer due to outdated notebookjs
CVE-2026-52797High· 8.5Gogs: Overwriting critical files results in a denial of service
Gogs: Overwriting critical files results in a denial of service
CVE-2021-32546CriticalOS Command Injection in gogs
OS Command Injection in gogs