Vendor CVEs
Gogs
All CVEs
77 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-8110 | Hig | 0.69 | 8.8 | 0.83 | KEV | Dec 10, 2025 | Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code. | |
| CVE-2024-39931 | Cri | 0.68 | 9.9 | 0.53 | Jul 4, 2024 | Gogs through 0.13.0 allows deletion of internal files. | ||
| CVE-2024-39932 | Cri | 0.66 | 9.9 | 0.17 | Jul 4, 2024 | Gogs through 0.13.0 allows argument injection during the previewing of changes. | ||
| CVE-2018-18925 | Cri | 0.66 | 9.8 | 0.31 | Nov 4, 2018 | Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery in the file session provider in file.go. This is related to session ID handling in the go-macaron/session code for Macaron. | ||
| CVE-2022-2024 | Cri | 0.65 | 9.8 | 0.98 | Feb 25, 2023 | OS Command Injection in GitHub repository gogs/gogs prior to 0.12.11. | ||
| CVE-2022-32174 | Cri | 0.63 | 9.0 | 0.58 | Oct 11, 2022 | In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover. | ||
| CVE-2024-39930 | Cri | 0.61 | 9.9 | 0.08 | Jul 4, 2024 | The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution. Authenticated attackers can exploit this by opening an SSH connection and sending a malicious --split-string env request if the built-in SSH server… | ||
| CVE-2026-52806 | Cri | 0.60 | 9.9 | 0.01 | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code Execution (RCE) on the server by creating a pull request with a specially crafted branch name that injects the --exec flag into the git rebase command during… | ||
| CVE-2026-52813 | Cri | 0.58 | 10.0 | 0.01 | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization names containing path traversal sequences (../) are accepted by Gogs, and repositories under them are written to paths following these path traversals. This allows storing/retrieving data for… | ||
| CVE-2024-56731 | Cri | 0.58 | 10.0 | 0.01 | Jun 24, 2025 | Gogs is an open source self-hosted Git service. Prior to version 0.13.3, it's still possible to delete files under the .git directory and achieve remote command execution due to an insufficient patch for CVE-2024-39931. Unprivileged user accounts can execute arbitrary commands… | ||
| CVE-2024-44625 | Hig | 0.58 | 8.8 | 0.15 | Nov 15, 2024 | Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go. | ||
| CVE-2026-25242 | Cri | 0.57 | 9.8 | 0.01 | Feb 19, 2026 | Gogs is an open source self-hosted Git service. Versions 0.13.4 and below expose unauthenticated file upload endpoints by default. When the global RequireSigninView setting is disabled (default), any remote user can upload arbitrary files to the server via /releases/attachments… | ||
| CVE-2025-64111 | Cri | 0.57 | 9.8 | 0.01 | Feb 6, 2026 | Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, due to the insufficient patch for CVE-2024-56731, it's still possible to update files in the .git directory and achieve remote command execution. This issue has been patched in versions 0.13.4 and… | ||
| CVE-2024-54148 | Cri | 0.57 | 9.8 | 0.01 | Dec 23, 2024 | Gogs is an open source self-hosted Git service. A malicious user is able to commit and edit a crafted symlink file to a repository to gain SSH access to the server. The vulnerability is fixed in 0.13.1. | ||
| CVE-2022-1986 | Cri | 0.57 | 9.8 | 0.04 | Jun 9, 2022 | OS Command Injection in GitHub repository gogs/gogs prior to 0.12.9. | ||
| CVE-2020-15867 | Hig | 0.57 | 7.2 | 0.87 | Oct 16, 2020 | The git hook feature in Gogs 0.5.5 through 0.12.2 allows for authenticated remote code execution. There can be a privilege escalation if access to this hook feature is granted to a user who does not have administrative privileges. NOTE: because this is mentioned in the… | ||
| CVE-2019-14544 | Cri | 0.57 | 9.8 | 0.02 | Aug 2, 2019 | routes/api/v1/api.go in Gogs 0.11.86 lacks permission checks for routes: deploy keys, collaborators, and hooks. | ||
| CVE-2018-15193 | Hig | 0.57 | 8.8 | 0.01 | Aug 8, 2018 | A CSRF vulnerability in the admin panel in Gogs through 0.11.53 allows remote attackers to execute admin operations via a crafted issue / link. | ||
| CVE-2024-55947 | Hig | 0.56 | 8.8 | 0.75 | Dec 23, 2024 | Gogs is an open source self-hosted Git service. A malicious user is able to write a file to an arbitrary path on the server to gain SSH access to the server. The vulnerability is fixed in 0.13.1. | ||
| CVE-2018-16409 | Hig | 0.56 | 8.6 | 0.01 | Sep 3, 2018 | In Gogs 0.11.53, an attacker can use migrate to send arbitrary HTTP GET requests, leading to SSRF. | ||
| CVE-2022-0415 | Hig | 0.55 | 8.8 | 0.65 | Mar 21, 2022 | Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6. | ||
| CVE-2026-25921 | Cri | 0.53 | 9.3 | 0.00 | Mar 5, 2026 | Gogs is an open source self-hosted Git service. Prior to version 0.14.2, overwritable LFS object across different repos leads to supply-chain attack, all LFS objects are vulnerable to be maliciously overwritten by malicious attackers. This issue has been patched in version… | ||
| CVE-2026-52811 | Cri | 0.52 | — | 0.00 | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, (*Repository).UploadRepoFiles checks for symlinks only on the leaf of the upload target (osx.IsSymlink(targetPath)). The siblings UpdateRepoFile, DeleteRepoFile, and GetDiffPreview use hasSymlinkInPath, which… | ||
| CVE-2022-1992 | Cri | 0.52 | 9.1 | 0.02 | Jun 9, 2022 | Path Traversal in GitHub repository gogs/gogs prior to 0.12.9. | ||
| CVE-2022-0871 | Cri | 0.52 | 9.1 | 0.01 | Mar 11, 2022 | Missing Authorization in GitHub repository gogs/gogs prior to 0.12.5. | ||
| CVE-2026-52798 | Hig | 0.51 | 8.9 | 0.00 | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, although .ipynb previews are sanitized on the server side via /-/api/sanitize_ipynb, the inserted content is re-rendered on the client side without sanitization using marked() on elements with the .nb-markdown-cell… | ||
| CVE-2026-52805 | Hig | 0.50 | 8.7 | 0.00 | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, a Server-Side Request Forgery (SSRF) vulnerability exists in the repository migration functionality. The application validates only the initially submitted URL hostname, but git clone --mirror follows HTTP… | ||
| CVE-2026-52800 | Hig | 0.50 | 8.8 | 0.00 | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization team member management can be performed via GET requests without CSRF protection. If a victim who is an organization owner is logged in and is tricked into visiting a crafted link, an… | ||
| CVE-2026-26022 | Hig | 0.50 | 8.7 | 0.00 | Mar 5, 2026 | Gogs is an open source self-hosted Git service. Prior to version 0.14.2, a stored cross-site scripting (XSS) vulnerability exists in the comment and issue description functionality. The application's HTML sanitizer explicitly allows data: URI schemes, enabling authenticated… | ||
| CVE-2026-25232 | Hig | 0.50 | 8.8 | 0.00 | Feb 19, 2026 | Gogs is an open source self-hosted Git service. Versions 0.13.4 and below have an access control bypass vulnerability which allows any repository collaborator with Write permissions to delete protected branches (including the default branch) by sending a direct POST request,… | ||
| CVE-2025-64175 | Hig | 0.50 | 8.8 | 0.00 | Feb 6, 2026 | Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, Gogs’ 2FA recovery code validation does not scope codes by user, enabling cross-account bypass. If an attacker knows a victim’s username and password, they can use any unused recovery code (e.g.,… | ||
| CVE-2022-1993 | Hig | 0.50 | 8.1 | 0.52 | Jun 9, 2022 | Path Traversal in GitHub repository gogs/gogs prior to 0.12.9. | ||
| CVE-2018-15192 | Hig | 0.49 | 8.6 | 0.02 | Aug 8, 2018 | An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access intranet services. | ||
| CVE-2026-52797 | Hig | 0.48 | 8.5 | 0.00 | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.0, as an authorized user, an intruder can dictate the value which is passed to the git diff command which, together with bypassing the filtering of the passed value, allows the user to bypass the target directory and… | ||
| CVE-2026-47267 | Hig | 0.47 | 8.3 | 0.00 | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, the fix for CVE-2022-1285 prevents adding webooks or running webhooks with URLs with a hostname that resolves in localCIDRs. However, webhooks still follow redirects allowing to access hostname inside localCIDRs.… | ||
| CVE-2026-52801 | Hig | 0.46 | 8.1 | 0.00 | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Gogs Mirror Settings functionality provide an alternative way from the well protected New Migration functionality for any authenticated users to import local repositories. This issue stems from a lack of… | ||
| CVE-2026-24135 | Hig | 0.46 | 8.1 | 0.01 | Feb 6, 2026 | Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, a path traversal vulnerability exists in the updateWikiPage function of Gogs. The vulnerability allows an authenticated user with write access to a repository's wiki to delete arbitrary files on the… | ||
| CVE-2026-25119 | Hig | 0.43 | — | 0.01 | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, when ENABLE_REVERSE_PROXY_AUTHENTICATION is enabled, Gogs accepts the configured authentication header (default: X-WEBAUTH-USER) directly from client requests without validating that the request originated from a… | ||
| CVE-2024-39933 | Hig | 0.43 | 7.7 | 0.01 | Jul 4, 2024 | Gogs through 0.13.0 allows argument injection during the tagging of a new release. | ||
| CVE-2026-52799 | Hig | 0.42 | 7.5 | 0.00 | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, GET /attachments/:uuid returns the raw attachment file without verifying whether the requester has view permission for the associated Issue/Comment/Release or the repository. In a test environment with… | ||
| CVE-2018-20303 | Hig | 0.42 | 7.5 | 0.03 | Dec 20, 2018 | In pkg/tool/path.go in Gogs before 0.11.82.1218, a directory traversal in the file-upload functionality can allow an attacker to create a file under data/sessions on the server, a similar issue to CVE-2018-18925. | ||
| CVE-2026-26276 | Hig | 0.40 | 7.3 | 0.00 | Mar 5, 2026 | Gogs is an open source self-hosted Git service. Prior to version 0.14.2, an attacker can store an HTML/JavaScript payload in a repository’s Milestone name, and when another user selects that Milestone on the New Issue page (/issues/new), a DOM-Based XSS is triggered. This… | ||
| CVE-2026-26194 | Hig | 0.40 | 7.3 | 0.01 | Mar 5, 2026 | Gogs is an open source self-hosted Git service. Prior to version 0.14.2, there's a security issue in gogs where deleting a release can fail if a user controlled tag name is passed to git without the right separator, this lets git options get injected and mess with the process.… | ||
| CVE-2026-52812 | Hig | 0.39 | — | 0.00 | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, Git LFS storage is content-addressed by OID alone (/<oid[0]>/<oid[1]>/) but per-repo authorization lives in the lfs_object table keyed (repo_id, oid). serveUpload skips re-uploading when the OID file… | ||
| CVE-2026-52810 | Hig | 0.39 | — | 0.00 | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, Git smart HTTP authorizes POST …/git-receive-pack using the client-supplied service query string (so ?service=git-upload-pack is evaluated as read access) while routing still runs git receive-pack, allowing push… | ||
| CVE-2026-52808 | Hig | 0.39 | 7.1 | 0.00 | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, three API endpoints — PATCH /api/v1/repos/:owner/:repo/issue-tracker, PATCH /api/v1/repos/:owner/:repo/wiki, and POST /api/v1/repos/:owner/:repo/mirror-sync — are gated by reqRepoWriter() rather than… | ||
| CVE-2020-9329 | Med | 0.38 | 5.9 | 0.01 | Feb 21, 2020 | Gogs through 0.11.91 allows attackers to violate the admin-specified repo-creation policy due to an internal/db/repo.go race condition. | ||
| CVE-2026-52809 | Med | 0.37 | 6.8 | 0.00 | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, password-reset tokens are generated using conf.Auth.ActivateCodeLives (the account-activation lifetime), not conf.Auth.ResetPasswordCodeLives. The token lifetime is baked into the token itself at generation time… | ||
| CVE-2026-25229 | Med | 0.35 | 6.5 | 0.00 | Feb 19, 2026 | Gogs is an open source self-hosted Git service. Versions 0.13.4 and below have a broken access control vulnerability which allows authenticated users with write access to any repository to modify labels belonging to other repositories. The UpdateLabel function in the Web UI… | ||
| CVE-2026-23633 | Med | 0.35 | 6.5 | 0.00 | Feb 6, 2026 | Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, there is an arbitrary file read/write via path traversal in Git hook editing. This issue has been patched in versions 0.13.4 and 0.14.0+dev. |
- risk 0.69cvss 8.8epss 0.83
Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.
- risk 0.68cvss 9.9epss 0.53
Gogs through 0.13.0 allows deletion of internal files.
- risk 0.66cvss 9.9epss 0.17
Gogs through 0.13.0 allows argument injection during the previewing of changes.
- risk 0.66cvss 9.8epss 0.31
Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery in the file session provider in file.go. This is related to session ID handling in the go-macaron/session code for Macaron.
- risk 0.65cvss 9.8epss 0.98
OS Command Injection in GitHub repository gogs/gogs prior to 0.12.11.
- risk 0.63cvss 9.0epss 0.58
In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover.
- risk 0.61cvss 9.9epss 0.08
The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution. Authenticated attackers can exploit this by opening an SSH connection and sending a malicious --split-string env request if the built-in SSH server…
- risk 0.60cvss 9.9epss 0.01
Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code Execution (RCE) on the server by creating a pull request with a specially crafted branch name that injects the --exec flag into the git rebase command during…
- risk 0.58cvss 10.0epss 0.01
Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization names containing path traversal sequences (../) are accepted by Gogs, and repositories under them are written to paths following these path traversals. This allows storing/retrieving data for…
- risk 0.58cvss 10.0epss 0.01
Gogs is an open source self-hosted Git service. Prior to version 0.13.3, it's still possible to delete files under the .git directory and achieve remote command execution due to an insufficient patch for CVE-2024-39931. Unprivileged user accounts can execute arbitrary commands…
- risk 0.58cvss 8.8epss 0.15
Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go.
- risk 0.57cvss 9.8epss 0.01
Gogs is an open source self-hosted Git service. Versions 0.13.4 and below expose unauthenticated file upload endpoints by default. When the global RequireSigninView setting is disabled (default), any remote user can upload arbitrary files to the server via /releases/attachments…
- risk 0.57cvss 9.8epss 0.01
Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, due to the insufficient patch for CVE-2024-56731, it's still possible to update files in the .git directory and achieve remote command execution. This issue has been patched in versions 0.13.4 and…
- risk 0.57cvss 9.8epss 0.01
Gogs is an open source self-hosted Git service. A malicious user is able to commit and edit a crafted symlink file to a repository to gain SSH access to the server. The vulnerability is fixed in 0.13.1.
- risk 0.57cvss 9.8epss 0.04
OS Command Injection in GitHub repository gogs/gogs prior to 0.12.9.
- risk 0.57cvss 7.2epss 0.87
The git hook feature in Gogs 0.5.5 through 0.12.2 allows for authenticated remote code execution. There can be a privilege escalation if access to this hook feature is granted to a user who does not have administrative privileges. NOTE: because this is mentioned in the…
- risk 0.57cvss 9.8epss 0.02
routes/api/v1/api.go in Gogs 0.11.86 lacks permission checks for routes: deploy keys, collaborators, and hooks.
- risk 0.57cvss 8.8epss 0.01
A CSRF vulnerability in the admin panel in Gogs through 0.11.53 allows remote attackers to execute admin operations via a crafted issue / link.
- risk 0.56cvss 8.8epss 0.75
Gogs is an open source self-hosted Git service. A malicious user is able to write a file to an arbitrary path on the server to gain SSH access to the server. The vulnerability is fixed in 0.13.1.
- risk 0.56cvss 8.6epss 0.01
In Gogs 0.11.53, an attacker can use migrate to send arbitrary HTTP GET requests, leading to SSRF.
- risk 0.55cvss 8.8epss 0.65
Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6.
- risk 0.53cvss 9.3epss 0.00
Gogs is an open source self-hosted Git service. Prior to version 0.14.2, overwritable LFS object across different repos leads to supply-chain attack, all LFS objects are vulnerable to be maliciously overwritten by malicious attackers. This issue has been patched in version…
- risk 0.52cvss —epss 0.00
Gogs is an open source self-hosted Git service. Prior to 0.14.3, (*Repository).UploadRepoFiles checks for symlinks only on the leaf of the upload target (osx.IsSymlink(targetPath)). The siblings UpdateRepoFile, DeleteRepoFile, and GetDiffPreview use hasSymlinkInPath, which…
- risk 0.52cvss 9.1epss 0.02
Path Traversal in GitHub repository gogs/gogs prior to 0.12.9.
- risk 0.52cvss 9.1epss 0.01
Missing Authorization in GitHub repository gogs/gogs prior to 0.12.5.
- risk 0.51cvss 8.9epss 0.00
Gogs is an open source self-hosted Git service. Prior to 0.14.3, although .ipynb previews are sanitized on the server side via /-/api/sanitize_ipynb, the inserted content is re-rendered on the client side without sanitization using marked() on elements with the .nb-markdown-cell…
- risk 0.50cvss 8.7epss 0.00
Gogs is an open source self-hosted Git service. Prior to 0.14.3, a Server-Side Request Forgery (SSRF) vulnerability exists in the repository migration functionality. The application validates only the initially submitted URL hostname, but git clone --mirror follows HTTP…
- risk 0.50cvss 8.8epss 0.00
Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization team member management can be performed via GET requests without CSRF protection. If a victim who is an organization owner is logged in and is tricked into visiting a crafted link, an…
- risk 0.50cvss 8.7epss 0.00
Gogs is an open source self-hosted Git service. Prior to version 0.14.2, a stored cross-site scripting (XSS) vulnerability exists in the comment and issue description functionality. The application's HTML sanitizer explicitly allows data: URI schemes, enabling authenticated…
- risk 0.50cvss 8.8epss 0.00
Gogs is an open source self-hosted Git service. Versions 0.13.4 and below have an access control bypass vulnerability which allows any repository collaborator with Write permissions to delete protected branches (including the default branch) by sending a direct POST request,…
- risk 0.50cvss 8.8epss 0.00
Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, Gogs’ 2FA recovery code validation does not scope codes by user, enabling cross-account bypass. If an attacker knows a victim’s username and password, they can use any unused recovery code (e.g.,…
- risk 0.50cvss 8.1epss 0.52
Path Traversal in GitHub repository gogs/gogs prior to 0.12.9.
- risk 0.49cvss 8.6epss 0.02
An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access intranet services.
- risk 0.48cvss 8.5epss 0.00
Gogs is an open source self-hosted Git service. Prior to 0.14.0, as an authorized user, an intruder can dictate the value which is passed to the git diff command which, together with bypassing the filtering of the passed value, allows the user to bypass the target directory and…
- risk 0.47cvss 8.3epss 0.00
Gogs is an open source self-hosted Git service. Prior to 0.14.3, the fix for CVE-2022-1285 prevents adding webooks or running webhooks with URLs with a hostname that resolves in localCIDRs. However, webhooks still follow redirects allowing to access hostname inside localCIDRs.…
- risk 0.46cvss 8.1epss 0.00
Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Gogs Mirror Settings functionality provide an alternative way from the well protected New Migration functionality for any authenticated users to import local repositories. This issue stems from a lack of…
- risk 0.46cvss 8.1epss 0.01
Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, a path traversal vulnerability exists in the updateWikiPage function of Gogs. The vulnerability allows an authenticated user with write access to a repository's wiki to delete arbitrary files on the…
- risk 0.43cvss —epss 0.01
Gogs is an open source self-hosted Git service. Prior to 0.14.3, when ENABLE_REVERSE_PROXY_AUTHENTICATION is enabled, Gogs accepts the configured authentication header (default: X-WEBAUTH-USER) directly from client requests without validating that the request originated from a…
- risk 0.43cvss 7.7epss 0.01
Gogs through 0.13.0 allows argument injection during the tagging of a new release.
- risk 0.42cvss 7.5epss 0.00
Gogs is an open source self-hosted Git service. Prior to 0.14.3, GET /attachments/:uuid returns the raw attachment file without verifying whether the requester has view permission for the associated Issue/Comment/Release or the repository. In a test environment with…
- risk 0.42cvss 7.5epss 0.03
In pkg/tool/path.go in Gogs before 0.11.82.1218, a directory traversal in the file-upload functionality can allow an attacker to create a file under data/sessions on the server, a similar issue to CVE-2018-18925.
- risk 0.40cvss 7.3epss 0.00
Gogs is an open source self-hosted Git service. Prior to version 0.14.2, an attacker can store an HTML/JavaScript payload in a repository’s Milestone name, and when another user selects that Milestone on the New Issue page (/issues/new), a DOM-Based XSS is triggered. This…
- risk 0.40cvss 7.3epss 0.01
Gogs is an open source self-hosted Git service. Prior to version 0.14.2, there's a security issue in gogs where deleting a release can fail if a user controlled tag name is passed to git without the right separator, this lets git options get injected and mess with the process.…
- risk 0.39cvss —epss 0.00
Gogs is an open source self-hosted Git service. Prior to 0.14.3, Git LFS storage is content-addressed by OID alone (/<oid[0]>/<oid[1]>/) but per-repo authorization lives in the lfs_object table keyed (repo_id, oid). serveUpload skips re-uploading when the OID file…
- risk 0.39cvss —epss 0.00
Gogs is an open source self-hosted Git service. Prior to 0.14.3, Git smart HTTP authorizes POST …/git-receive-pack using the client-supplied service query string (so ?service=git-upload-pack is evaluated as read access) while routing still runs git receive-pack, allowing push…
- risk 0.39cvss 7.1epss 0.00
Gogs is an open source self-hosted Git service. Prior to 0.14.3, three API endpoints — PATCH /api/v1/repos/:owner/:repo/issue-tracker, PATCH /api/v1/repos/:owner/:repo/wiki, and POST /api/v1/repos/:owner/:repo/mirror-sync — are gated by reqRepoWriter() rather than…
- risk 0.38cvss 5.9epss 0.01
Gogs through 0.11.91 allows attackers to violate the admin-specified repo-creation policy due to an internal/db/repo.go race condition.
- risk 0.37cvss 6.8epss 0.00
Gogs is an open source self-hosted Git service. Prior to 0.14.3, password-reset tokens are generated using conf.Auth.ActivateCodeLives (the account-activation lifetime), not conf.Auth.ResetPasswordCodeLives. The token lifetime is baked into the token itself at generation time…
- risk 0.35cvss 6.5epss 0.00
Gogs is an open source self-hosted Git service. Versions 0.13.4 and below have a broken access control vulnerability which allows authenticated users with write access to any repository to modify labels belonging to other repositories. The UpdateLabel function in the Web UI…
- risk 0.35cvss 6.5epss 0.00
Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, there is an arbitrary file read/write via path traversal in Git hook editing. This issue has been patched in versions 0.13.4 and 0.14.0+dev.
Page 1 of 2