VYPR

Gogs

by Gogs

Source repositories

CVEs (77)

  • CVE-2022-0415HigMar 21, 2022
    risk 0.55cvss 8.8epss 0.65

    Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6.

  • CVE-2026-25921CriMar 5, 2026
    risk 0.53cvss 9.3epss 0.00

    Gogs is an open source self-hosted Git service. Prior to version 0.14.2, overwritable LFS object across different repos leads to supply-chain attack, all LFS objects are vulnerable to be maliciously overwritten by malicious attackers. This issue has been patched in version…

  • CVE-2026-52811CriJun 24, 2026
    risk 0.52cvss —epss 0.00

    Gogs is an open source self-hosted Git service. Prior to 0.14.3, (*Repository).UploadRepoFiles checks for symlinks only on the leaf of the upload target (osx.IsSymlink(targetPath)). The siblings UpdateRepoFile, DeleteRepoFile, and GetDiffPreview use hasSymlinkInPath, which…

  • CVE-2022-1992CriJun 9, 2022
    risk 0.52cvss 9.1epss 0.02

    Path Traversal in GitHub repository gogs/gogs prior to 0.12.9.

  • CVE-2022-0871CriMar 11, 2022
    risk 0.52cvss 9.1epss 0.01

    Missing Authorization in GitHub repository gogs/gogs prior to 0.12.5.

  • CVE-2026-52798HigJun 24, 2026
    risk 0.51cvss 8.9epss 0.00

    Gogs is an open source self-hosted Git service. Prior to 0.14.3, although .ipynb previews are sanitized on the server side via /-/api/sanitize_ipynb, the inserted content is re-rendered on the client side without sanitization using marked() on elements with the .nb-markdown-cell…

  • CVE-2026-52805HigJun 24, 2026
    risk 0.50cvss 8.7epss 0.00

    Gogs is an open source self-hosted Git service. Prior to 0.14.3, a Server-Side Request Forgery (SSRF) vulnerability exists in the repository migration functionality. The application validates only the initially submitted URL hostname, but git clone --mirror follows HTTP…

  • CVE-2026-52800HigJun 24, 2026
    risk 0.50cvss 8.8epss 0.00

    Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization team member management can be performed via GET requests without CSRF protection. If a victim who is an organization owner is logged in and is tricked into visiting a crafted link, an…

  • CVE-2026-26022HigMar 5, 2026
    risk 0.50cvss 8.7epss 0.00

    Gogs is an open source self-hosted Git service. Prior to version 0.14.2, a stored cross-site scripting (XSS) vulnerability exists in the comment and issue description functionality. The application's HTML sanitizer explicitly allows data: URI schemes, enabling authenticated…

  • CVE-2026-25232HigFeb 19, 2026
    risk 0.50cvss 8.8epss 0.00

    Gogs is an open source self-hosted Git service. Versions 0.13.4 and below have an access control bypass vulnerability which allows any repository collaborator with Write permissions to delete protected branches (including the default branch) by sending a direct POST request,…

  • CVE-2025-64175HigFeb 6, 2026
    risk 0.50cvss 8.8epss 0.00

    Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, Gogs’ 2FA recovery code validation does not scope codes by user, enabling cross-account bypass. If an attacker knows a victim’s username and password, they can use any unused recovery code (e.g.,…

  • CVE-2022-1993HigJun 9, 2022
    risk 0.49cvss 8.1epss 0.36

    Path Traversal in GitHub repository gogs/gogs prior to 0.12.9.

  • CVE-2018-15192HigAug 8, 2018
    risk 0.49cvss 8.6epss 0.02

    An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access intranet services.

  • CVE-2026-52797HigJun 24, 2026
    risk 0.48cvss 8.5epss 0.01

    Gogs is an open source self-hosted Git service. Prior to 0.14.0, as an authorized user, an intruder can dictate the value which is passed to the git diff command which, together with bypassing the filtering of the passed value, allows the user to bypass the target directory and…

  • CVE-2026-47267HigJun 24, 2026
    risk 0.47cvss 8.3epss 0.00

    Gogs is an open source self-hosted Git service. Prior to 0.14.3, the fix for CVE-2022-1285 prevents adding webooks or running webhooks with URLs with a hostname that resolves in localCIDRs. However, webhooks still follow redirects allowing to access hostname inside localCIDRs.…

  • CVE-2026-52801HigJun 24, 2026
    risk 0.46cvss 8.1epss 0.01

    Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Gogs Mirror Settings functionality provide an alternative way from the well protected New Migration functionality for any authenticated users to import local repositories. This issue stems from a lack of…

  • CVE-2026-24135HigFeb 6, 2026
    risk 0.46cvss 8.1epss 0.01

    Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, a path traversal vulnerability exists in the updateWikiPage function of Gogs. The vulnerability allows an authenticated user with write access to a repository's wiki to delete arbitrary files on the…

  • CVE-2026-25119HigJun 24, 2026
    risk 0.43cvss —epss 0.01

    Gogs is an open source self-hosted Git service. Prior to 0.14.3, when ENABLE_REVERSE_PROXY_AUTHENTICATION is enabled, Gogs accepts the configured authentication header (default: X-WEBAUTH-USER) directly from client requests without validating that the request originated from a…

  • CVE-2024-39933HigJul 4, 2024
    risk 0.43cvss 7.7epss 0.01

    Gogs through 0.13.0 allows argument injection during the tagging of a new release.

  • CVE-2026-52799HigJun 24, 2026
    risk 0.42cvss 7.5epss 0.00

    Gogs is an open source self-hosted Git service. Prior to 0.14.3, GET /attachments/:uuid returns the raw attachment file without verifying whether the requester has view permission for the associated Issue/Comment/Release or the repository. In a test environment with…