VulnSea

gogs.io/gogs vulnerabilities

CVEs whose affected-version data names the gogs.io/gogs package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

25 CVEsRSS

CVE-2026-52800High· 8.8
3mo ago

Gogs Vulnerable to CSRF Leading to Organization Owner Takeover

Gogs Vulnerable to CSRF Leading to Organization Owner Takeover

Twilightgogs · gogs.io/gogsEPSS 0.25%via GHSA
CVE-2026-52801High· 8.1
3mo ago

Gogs has the ability to import local repositories via Mirror Settings

Gogs has the ability to import local repositories via Mirror Settings

Twilightgogs · gogs.io/gogsEPSS 0.57%via GHSA
CVE-2026-52802Medium· 5.4
3mo ago

Gogs has an Open Redirect via redirect_to

Gogs has an Open Redirect via redirect_to

Sunlitgogs · gogs.io/gogsEPSS 0.55%via GHSA
CVE-2026-52804Medium
3mo ago

Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation

Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation

Sunlitgogs · gogs.io/gogsEPSS 0.50%via GHSA
CVE-2026-52805High· 8.7
3mo ago

Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft

Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft

Twilightgogs · gogs.io/gogsEPSS 0.38%via GHSA
CVE-2026-52806Critical· 9.9PoC
3mo ago

Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge

Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge

Abyssalgogs · gogs.io/gogsEPSS 7.9%via GHSA
CVE-2026-52807High
3mo ago

Gogs has DOM-based XSS via Milestone Name on New Issue Page

Gogs has DOM-based XSS via Milestone Name on New Issue Page

Twilightgogs · gogs.io/gogsEPSS 0.48%via GHSA
CVE-2026-52808High· 7.1
3mo ago

Gogs's write-level collaborators can mutate admin-only repository settings via API

Gogs's write-level collaborators can mutate admin-only repository settings via API

Twilightgogs · gogs.io/gogsEPSS 0.48%via GHSA
CVE-2026-52809Medium· 6.8
3mo ago

Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES

Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES

Sunlitgogs · gogs.io/gogsEPSS 0.20%via GHSA
CVE-2026-52810HighPoC
3mo ago

Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion

Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion

Midnightgogs · gogs.io/gogsEPSS 0.43%via GHSA
CVE-2026-52811Critical
3mo ago

Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym

Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym

Midnightgogs · gogs.io/gogsEPSS 0.47%via GHSA
CVE-2026-52812High
3mo ago

Gogs: LFS dedupe path leaks private repo content across tenants

Gogs: LFS dedupe path leaks private repo content across tenants

Twilightgogs · gogs.io/gogsEPSS 0.24%via GHSA
CVE-2026-52813Critical· 10.0PoC
3mo ago

Gogs has Path Traversal in organization name that results in RCE through Git hooks

Gogs has Path Traversal in organization name that results in RCE through Git hooks

Abyssalgogs · gogs.io/gogsEPSS 1.1%via GHSA
CVE-2026-52814Medium
3mo ago

Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion)

Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion)

Sunlitgogs · gogs.io/gogsEPSS 0.55%via GHSA
CVE-2026-52815MediumPoC
3mo ago

Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API

Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API

Twilightgogs · gogs.io/gogsEPSS 1.5%via GHSA
CVE-2026-52816Medium
3mo ago

Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS

Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS

Sunlitgogs · gogs.io/gogsEPSS 0.68%via GHSA
CVE-2025-64719Medium· 4.9
3mo ago

Gogs has a Denial of Service in repository/wiki file listing web pages

Gogs has a Denial of Service in repository/wiki file listing web pages

Sunlitgogs · gogs.io/gogsEPSS 0.44%via GHSA
CVE-2026-25119High
3mo ago

Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers

Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers

Twilightgogs · gogs.io/gogsEPSS 0.86%via GHSA
CVE-2026-47267Medium
3mo ago

Gogs has SSRF in webhook deliveries

Gogs has SSRF in webhook deliveries

Sunlitgogs · gogs.io/gogsEPSS 0.42%via GHSA
CVE-2026-52796Low· 3.5
3mo ago

Gogs has DoS in rendering issue index pattern

Gogs has DoS in rendering issue index pattern

Sunlitgogs · gogs.io/gogsEPSS 0.28%via GHSA
CVE-2026-52798High· 8.9
3mo ago

Gogs has Stored XSS in `.ipynb` Preview

Gogs has Stored XSS in `.ipynb` Preview

Twilightgogs · gogs.io/gogsEPSS 0.43%via GHSA
CVE-2026-52799High· 7.5
3mo ago

Gogs Missing Authorization in Attachment Download

Gogs Missing Authorization in Attachment Download

Twilightgogs · gogs.io/gogsEPSS 0.42%via GHSA
GHSA-6vxv-wg6j-5qwpHigh
3mo ago

Gogs: XSS in .ipynb files renderer due to outdated notebookjs

Gogs: XSS in .ipynb files renderer due to outdated notebookjs

Twilightgogs · gogs.io/gogsvia GHSA
CVE-2026-52797High· 8.5
3mo ago

Gogs: Overwriting critical files results in a denial of service

Gogs: Overwriting critical files results in a denial of service

Twilightgogs · gogs.io/gogsEPSS 0.53%via GHSA
CVE-2021-32546Critical
4y ago

OS Command Injection in gogs

OS Command Injection in gogs

Midnightgogs · gogs.io/gogsEPSS 2.1%via OSV
gogs.io/gogs vulnerabilities (CVEs) · VulnSea