Tagged “go”
CVEs tagged go, newest first.
1732 CVEsRSS
CVE-2026-52802Medium· 5.4Gogs has an Open Redirect via redirect_to
Gogs has an Open Redirect via redirect_to
CVE-2026-52804MediumGogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation
Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation
CVE-2026-52805High· 8.7Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft
Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft
CVE-2026-52806Critical· 9.9PoCGogs vulnerable to RCE via git rebase --exec argument injection in pull request merge
Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge
CVE-2026-52807HighGogs has DOM-based XSS via Milestone Name on New Issue Page
Gogs has DOM-based XSS via Milestone Name on New Issue Page
CVE-2026-52808High· 7.1Gogs's write-level collaborators can mutate admin-only repository settings via API
Gogs's write-level collaborators can mutate admin-only repository settings via API
CVE-2026-52809Medium· 6.8Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES
Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES
CVE-2026-52810HighPoCGogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion
Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion
CVE-2026-52811CriticalGogs: UploadRepoFiles writes outside repo working tree via committed parent sym
Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym
CVE-2026-52812HighGogs: LFS dedupe path leaks private repo content across tenants
Gogs: LFS dedupe path leaks private repo content across tenants
CVE-2026-52813Critical· 10.0PoCGogs has Path Traversal in organization name that results in RCE through Git hooks
Gogs has Path Traversal in organization name that results in RCE through Git hooks
CVE-2026-52814MediumGogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion)
Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion)
CVE-2026-52815MediumPoCGogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API
Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API
CVE-2026-52816MediumGogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS
Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS
CVE-2026-48126High· 8.2Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir
Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir
GHSA-wcmj-x466-56mmMedium· 6.1OpenTofu: Provider cache installation follows root-module-controlled package directory symlink and writes outside the working tree
OpenTofu: Provider cache installation follows root-module-controlled package directory symlink and writes outside the working tree
CVE-2026-8823Low· 3.8Mattermost has an Incorrect Authorization issue
Mattermost has an Incorrect Authorization issue
CVE-2026-12249Critical· 9.0Canonical ADSys Uses a Less Trusted Source
Canonical ADSys Uses a Less Trusted Source
CVE-2026-6673Medium· 6.4Mattermost doesn't authenticate Atlassian Connect installed callbacks, allowing a remote unauthenticated attacker to inject a rogue share…
Mattermost doesn't authenticate Atlassian Connect installed callbacks, allowing a remote unauthenticated attacker to inject a rogue sharedSecret
CVE-2026-6062Medium· 6.4Mattermost doesn't validate channel ownership of an existing subscription before applying edits
Mattermost doesn't validate channel ownership of an existing subscription before applying edits
CVE-2026-9162Medium· 4.3Mattermost doesn't invalidate cached authentication state for active WebSocket connections during global session revocation
Mattermost doesn't invalidate cached authentication state for active WebSocket connections during global session revocation
CVE-2026-8074Low· 3.8Mattermost doesn't enforce bot-specific permission checks on the user active status endpoint
Mattermost doesn't enforce bot-specific permission checks on the user active status endpoint
CVE-2026-5139Medium· 5.4Mattermost doesn't enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler
Mattermost doesn't enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler
CVE-2026-39904Medium· 6.5Gophish contains a denial of service vulnerability
Gophish contains a denial of service vulnerability
CVE-2026-42127High· 7.5The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads
The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of serv…
CVE-2026-9029High· 7.3A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable
A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored…
CVE-2026-42129High· 7.7A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information.
A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information.
CVE-2026-10601Medium· 5.4A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints
A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak inter…
CVE-2025-64719Medium· 4.9Gogs has a Denial of Service in repository/wiki file listing web pages
Gogs has a Denial of Service in repository/wiki file listing web pages
CVE-2026-25119HighGogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers
Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers