High severityNVD Advisory· Published Jun 24, 2026· Updated Jun 25, 2026
CVE-2026-25119
CVE-2026-25119
Description
Gogs is an open source self-hosted Git service. Prior to 0.14.3, when ENABLE_REVERSE_PROXY_AUTHENTICATION is enabled, Gogs accepts the configured authentication header (default: X-WEBAUTH-USER) directly from client requests without validating that the request originated from a trusted reverse proxy. Any remote attacker who can reach the Gogs service can forge this header to impersonate any user or trigger automatic account creation, completely bypassing authentication. This vulnerability is fixed in 0.14.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
gogs.io/gogsGo | < 0.14.3 | 0.14.3 |
Affected products
2- osv-coordsRange: < 0.0.20260723T184607-160000.1.1
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-w6j9-vw59-27wvghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-25119ghsaADVISORY
- github.com/gogs/gogs/commit/0089c4c8e5b8d99eb6e5c8727f8f40d765f1f58anvdWEB
- github.com/gogs/gogs/pull/8264nvdWEB
- github.com/gogs/gogs/releases/tag/v0.14.3nvdWEB
- github.com/gogs/gogs/security/advisories/GHSA-w6j9-vw59-27wvnvdWEB
News mentions
1- Gogs: 18 Vulnerabilities Including RCE and Auth Bypass Disclosed in BatchVypr Intelligence · Jun 24, 2026