gogs.io/gogs
Activity
- Latest release
- 1y ago
- Total releases
- 20
- Cadence
- ~daily
- Last 12 months
- 0
Details
- First release
- Mar 19, 2022
| Version | Released | |
|---|---|---|
v0.13.3
patch
45 CVEs
CVE-2026-52802
GO-2026-5773
GHSA-xxhq-69mf-w8cr
Jun 25, 2026
Gogs has an Open Redirect via redirect_to in gogs.io/gogs Gogs has an Open Redirect via redirect_to in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52814
GO-2026-5765
GHSA-xp79-5mx3-jx52
Jun 25, 2026
Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52801
GO-2026-5724
GHSA-wv27-2vqp-j7g5
Jun 25, 2026
Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-25119
GO-2026-5695
GHSA-w6j9-vw59-27wv
Jun 25, 2026
Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52810
GO-2026-5712
GHSA-wmfg-5p4h-5fw3
Jun 25, 2026
Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52807
GO-2026-5661
GHSA-vcm5-gvmp-78mp
Jun 25, 2026
Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52799
GO-2026-5536
GHSA-p9f5-h3rx-j5qw
Jun 25, 2026
Gogs Missing Authorization in Attachment Download in gogs.io/gogs Gogs Missing Authorization in Attachment Download in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52797
GO-2026-5545
GHSA-pm6v-2h4w-4rp2
Jun 25, 2026
Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52806
GO-2026-5580
GHSA-qf6p-p7ww-cwr9
Jun 25, 2026
Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52800
GO-2026-5556
GHSA-pwx3-qcgw-vh7h
Jun 25, 2026
Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52808
GO-2026-5065
GHSA-268j-37xf-pp52
Jun 25, 2026
Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52798
GO-2026-5477
GHSA-jq8v-rmf6-65jw
Jun 25, 2026
Gogs has Stored XSS in `.ipynb` Preview in gogs.io/gogs Gogs has Stored XSS in NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52805
GO-2026-5387
GHSA-g2f5-gjr4-qjvm
Jun 25, 2026
Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47267
GO-2026-5312
GHSA-c4v7-xg93-qf8g
Jun 25, 2026
Gogs has SSRF in webhook deliveries in gogs.io/gogs Gogs has SSRF in webhook deliveries in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52813
GO-2026-5305
GHSA-c39w-43gm-34h5
Jun 25, 2026
Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5193
GHSA-6vxv-wg6j-5qwp
Jun 25, 2026
Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52815
GO-2026-5202
GHSA-744x-3838-5r56
Jun 25, 2026
Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52812
GO-2026-5184
GHSA-6p9m-q3jp-47h4
Jun 25, 2026
Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52811
GO-2026-5249
GHSA-89mr-xqfv-758m
Jun 25, 2026
Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-64719
GO-2026-5098
GHSA-3qq3-668m-v9mj
Jun 25, 2026
Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52816
GO-2026-5103
GHSA-3w28-36p9-w929
Jun 25, 2026
Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52809
GO-2026-5140
GHSA-5c3f-6486-3g7g
Jun 25, 2026
Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52804
GO-2026-5110
GHSA-4565-r4x7-hg8j
Jun 25, 2026
Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52796
GO-2026-5124
GHSA-4j89-2c4f-44c6
Jun 25, 2026
Gogs has DoS in rendering issue index pattern in gogs.io/gogs Gogs has DoS in rendering issue index pattern in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-25921
GO-2026-4616
GHSA-cj4v-437j-jq4c
Mar 10, 2026
Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26195
GO-2026-4618
GHSA-vgvf-m4fw-938j
Mar 10, 2026
Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26276
GO-2026-4627
GHSA-vgjm-2cpf-4g7c
Mar 10, 2026
Gogs: DOM-based XSS via milestone selection in gogs.io/gogs Gogs: DOM-based XSS via milestone selection in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26022
GO-2026-4620
GHSA-xrcr-gmf5-2r8j
Mar 10, 2026
Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26194
GO-2026-4617
GHSA-v9vm-r24h-6rqm
Mar 10, 2026
Gogs: Release tag option injection in release deletion in gogs.io/gogs Gogs: Release tag option injection in release deletion in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26196
GO-2026-4619
GHSA-x9p5-w45c-7ffc
Mar 10, 2026
Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-25229
GO-2026-4499
GHSA-cv22-72px-f4gh
Feb 23, 2026
Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25232
GO-2026-4498
GHSA-2c6v-8r3v-gh6p
Feb 23, 2026
Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.1. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25120
GO-2026-4501
GHSA-jj5m-h57j-5gv7
Feb 23, 2026
Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25242
GO-2026-4500
GHSA-fc3h-92p8-h36f
Feb 23, 2026
Unauthenticated File Upload in Gogs in gogs.io/gogs Unauthenticated File Upload in Gogs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.1. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-23632
GO-2026-4450
GHSA-5qhx-gwfj-6jqr
Feb 17, 2026
Gogs user can update repository content with read-only permission in gogs.io/gogs Gogs user can update repository content with read-only permission in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4454
GHSA-26gq-grmh-6xm6
Feb 17, 2026
Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References
Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-64175
GO-2026-4449
GHSA-p6x6-9mx6-26wj
Feb 17, 2026
Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-23633
GO-2026-4453
GHSA-mrph-w4hh-gx3g
Feb 17, 2026
Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24135
GO-2026-4452
GHSA-jp7c-wj6q-3qf2
Feb 17, 2026
Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65852
GO-2026-4457
GHSA-rjv5-9px2-fqw6
Feb 17, 2026
Gogs has authorization bypass in repository deletion API in gogs.io/gogs Gogs has authorization bypass in repository deletion API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-64111
GO-2026-4448
GHSA-gg64-xxr9-qhjp
Feb 17, 2026
Gogs's update .git/config file allows remote command execution in gogs.io/gogs Gogs's update .git/config file allows remote command execution in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-22592
GO-2026-4451
GHSA-cr88-6mqm-4g57
Feb 17, 2026
Gogs has a Denial of Service issue in gogs.io/gogs Gogs has a Denial of Service issue in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References
Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-8110
GO-2025-4225
GHSA-mq8m-42gh-wq7r
Dec 15, 2025
Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-44625
GO-2024-3275
GHSA-phm4-wf3h-pc3r
Nov 19, 2024
Unpatched Remote Code Execution in Gogs in gogs.io/gogs Unpatched Remote Code Execution in Gogs in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-32174
GO-2022-1060
GHSA-mcjj-2fvq-mc3r
Aug 21, 2024
Gogs vulnerable to Cross-site Scripting in gogs.io/gogs Gogs vulnerable to Cross-site Scripting in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev |
v0.13.3
patch
Dependencies (57)
+ 49 more |
|
v0.13.3-rc.1
pre
46 CVEs
CVE-2026-52802
GO-2026-5773
GHSA-xxhq-69mf-w8cr
Jun 25, 2026
Gogs has an Open Redirect via redirect_to in gogs.io/gogs Gogs has an Open Redirect via redirect_to in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52814
GO-2026-5765
GHSA-xp79-5mx3-jx52
Jun 25, 2026
Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52801
GO-2026-5724
GHSA-wv27-2vqp-j7g5
Jun 25, 2026
Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-25119
GO-2026-5695
GHSA-w6j9-vw59-27wv
Jun 25, 2026
Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52810
GO-2026-5712
GHSA-wmfg-5p4h-5fw3
Jun 25, 2026
Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52807
GO-2026-5661
GHSA-vcm5-gvmp-78mp
Jun 25, 2026
Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52799
GO-2026-5536
GHSA-p9f5-h3rx-j5qw
Jun 25, 2026
Gogs Missing Authorization in Attachment Download in gogs.io/gogs Gogs Missing Authorization in Attachment Download in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52797
GO-2026-5545
GHSA-pm6v-2h4w-4rp2
Jun 25, 2026
Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52806
GO-2026-5580
GHSA-qf6p-p7ww-cwr9
Jun 25, 2026
Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52800
GO-2026-5556
GHSA-pwx3-qcgw-vh7h
Jun 25, 2026
Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52808
GO-2026-5065
GHSA-268j-37xf-pp52
Jun 25, 2026
Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52798
GO-2026-5477
GHSA-jq8v-rmf6-65jw
Jun 25, 2026
Gogs has Stored XSS in `.ipynb` Preview in gogs.io/gogs Gogs has Stored XSS in NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52805
GO-2026-5387
GHSA-g2f5-gjr4-qjvm
Jun 25, 2026
Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47267
GO-2026-5312
GHSA-c4v7-xg93-qf8g
Jun 25, 2026
Gogs has SSRF in webhook deliveries in gogs.io/gogs Gogs has SSRF in webhook deliveries in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52813
GO-2026-5305
GHSA-c39w-43gm-34h5
Jun 25, 2026
Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5193
GHSA-6vxv-wg6j-5qwp
Jun 25, 2026
Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52815
GO-2026-5202
GHSA-744x-3838-5r56
Jun 25, 2026
Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52812
GO-2026-5184
GHSA-6p9m-q3jp-47h4
Jun 25, 2026
Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52811
GO-2026-5249
GHSA-89mr-xqfv-758m
Jun 25, 2026
Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-64719
GO-2026-5098
GHSA-3qq3-668m-v9mj
Jun 25, 2026
Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52816
GO-2026-5103
GHSA-3w28-36p9-w929
Jun 25, 2026
Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52809
GO-2026-5140
GHSA-5c3f-6486-3g7g
Jun 25, 2026
Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52804
GO-2026-5110
GHSA-4565-r4x7-hg8j
Jun 25, 2026
Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52796
GO-2026-5124
GHSA-4j89-2c4f-44c6
Jun 25, 2026
Gogs has DoS in rendering issue index pattern in gogs.io/gogs Gogs has DoS in rendering issue index pattern in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-25921
GO-2026-4616
GHSA-cj4v-437j-jq4c
Mar 10, 2026
Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26195
GO-2026-4618
GHSA-vgvf-m4fw-938j
Mar 10, 2026
Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26276
GO-2026-4627
GHSA-vgjm-2cpf-4g7c
Mar 10, 2026
Gogs: DOM-based XSS via milestone selection in gogs.io/gogs Gogs: DOM-based XSS via milestone selection in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26022
GO-2026-4620
GHSA-xrcr-gmf5-2r8j
Mar 10, 2026
Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26194
GO-2026-4617
GHSA-v9vm-r24h-6rqm
Mar 10, 2026
Gogs: Release tag option injection in release deletion in gogs.io/gogs Gogs: Release tag option injection in release deletion in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26196
GO-2026-4619
GHSA-x9p5-w45c-7ffc
Mar 10, 2026
Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-25229
GO-2026-4499
GHSA-cv22-72px-f4gh
Feb 23, 2026
Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25232
GO-2026-4498
GHSA-2c6v-8r3v-gh6p
Feb 23, 2026
Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.1. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25120
GO-2026-4501
GHSA-jj5m-h57j-5gv7
Feb 23, 2026
Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25242
GO-2026-4500
GHSA-fc3h-92p8-h36f
Feb 23, 2026
Unauthenticated File Upload in Gogs in gogs.io/gogs Unauthenticated File Upload in Gogs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.1. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-23632
GO-2026-4450
GHSA-5qhx-gwfj-6jqr
Feb 17, 2026
Gogs user can update repository content with read-only permission in gogs.io/gogs Gogs user can update repository content with read-only permission in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4454
GHSA-26gq-grmh-6xm6
Feb 17, 2026
Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References
Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-64175
GO-2026-4449
GHSA-p6x6-9mx6-26wj
Feb 17, 2026
Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-23633
GO-2026-4453
GHSA-mrph-w4hh-gx3g
Feb 17, 2026
Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24135
GO-2026-4452
GHSA-jp7c-wj6q-3qf2
Feb 17, 2026
Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65852
GO-2026-4457
GHSA-rjv5-9px2-fqw6
Feb 17, 2026
Gogs has authorization bypass in repository deletion API in gogs.io/gogs Gogs has authorization bypass in repository deletion API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-64111
GO-2026-4448
GHSA-gg64-xxr9-qhjp
Feb 17, 2026
Gogs's update .git/config file allows remote command execution in gogs.io/gogs Gogs's update .git/config file allows remote command execution in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-22592
GO-2026-4451
GHSA-cr88-6mqm-4g57
Feb 17, 2026
Gogs has a Denial of Service issue in gogs.io/gogs Gogs has a Denial of Service issue in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References
Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-8110
GO-2025-4225
GHSA-mq8m-42gh-wq7r
Dec 15, 2025
Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-56731
GO-2025-3776
GHSA-wj44-9vcg-wjq7
Jul 28, 2025
Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs Fixed in
0.13.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-44625
GO-2024-3275
GHSA-phm4-wf3h-pc3r
Nov 19, 2024
Unpatched Remote Code Execution in Gogs in gogs.io/gogs Unpatched Remote Code Execution in Gogs in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-32174
GO-2022-1060
GHSA-mcjj-2fvq-mc3r
Aug 21, 2024
Gogs vulnerable to Cross-site Scripting in gogs.io/gogs Gogs vulnerable to Cross-site Scripting in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev |
v0.13.3-rc.1
pre
Dependencies (57)
+ 49 more |
|
v0.13.2-rc.1
pre
47 CVEs
CVE-2026-52802
GO-2026-5773
GHSA-xxhq-69mf-w8cr
Jun 25, 2026
Gogs has an Open Redirect via redirect_to in gogs.io/gogs Gogs has an Open Redirect via redirect_to in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52814
GO-2026-5765
GHSA-xp79-5mx3-jx52
Jun 25, 2026
Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52801
GO-2026-5724
GHSA-wv27-2vqp-j7g5
Jun 25, 2026
Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-25119
GO-2026-5695
GHSA-w6j9-vw59-27wv
Jun 25, 2026
Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52810
GO-2026-5712
GHSA-wmfg-5p4h-5fw3
Jun 25, 2026
Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52807
GO-2026-5661
GHSA-vcm5-gvmp-78mp
Jun 25, 2026
Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52799
GO-2026-5536
GHSA-p9f5-h3rx-j5qw
Jun 25, 2026
Gogs Missing Authorization in Attachment Download in gogs.io/gogs Gogs Missing Authorization in Attachment Download in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52797
GO-2026-5545
GHSA-pm6v-2h4w-4rp2
Jun 25, 2026
Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52806
GO-2026-5580
GHSA-qf6p-p7ww-cwr9
Jun 25, 2026
Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52800
GO-2026-5556
GHSA-pwx3-qcgw-vh7h
Jun 25, 2026
Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52808
GO-2026-5065
GHSA-268j-37xf-pp52
Jun 25, 2026
Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52798
GO-2026-5477
GHSA-jq8v-rmf6-65jw
Jun 25, 2026
Gogs has Stored XSS in `.ipynb` Preview in gogs.io/gogs Gogs has Stored XSS in NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52805
GO-2026-5387
GHSA-g2f5-gjr4-qjvm
Jun 25, 2026
Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47267
GO-2026-5312
GHSA-c4v7-xg93-qf8g
Jun 25, 2026
Gogs has SSRF in webhook deliveries in gogs.io/gogs Gogs has SSRF in webhook deliveries in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52813
GO-2026-5305
GHSA-c39w-43gm-34h5
Jun 25, 2026
Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5193
GHSA-6vxv-wg6j-5qwp
Jun 25, 2026
Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52815
GO-2026-5202
GHSA-744x-3838-5r56
Jun 25, 2026
Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52812
GO-2026-5184
GHSA-6p9m-q3jp-47h4
Jun 25, 2026
Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52811
GO-2026-5249
GHSA-89mr-xqfv-758m
Jun 25, 2026
Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-64719
GO-2026-5098
GHSA-3qq3-668m-v9mj
Jun 25, 2026
Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52816
GO-2026-5103
GHSA-3w28-36p9-w929
Jun 25, 2026
Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52809
GO-2026-5140
GHSA-5c3f-6486-3g7g
Jun 25, 2026
Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52804
GO-2026-5110
GHSA-4565-r4x7-hg8j
Jun 25, 2026
Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52796
GO-2026-5124
GHSA-4j89-2c4f-44c6
Jun 25, 2026
Gogs has DoS in rendering issue index pattern in gogs.io/gogs Gogs has DoS in rendering issue index pattern in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-25921
GO-2026-4616
GHSA-cj4v-437j-jq4c
Mar 10, 2026
Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26195
GO-2026-4618
GHSA-vgvf-m4fw-938j
Mar 10, 2026
Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26276
GO-2026-4627
GHSA-vgjm-2cpf-4g7c
Mar 10, 2026
Gogs: DOM-based XSS via milestone selection in gogs.io/gogs Gogs: DOM-based XSS via milestone selection in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26022
GO-2026-4620
GHSA-xrcr-gmf5-2r8j
Mar 10, 2026
Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26194
GO-2026-4617
GHSA-v9vm-r24h-6rqm
Mar 10, 2026
Gogs: Release tag option injection in release deletion in gogs.io/gogs Gogs: Release tag option injection in release deletion in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26196
GO-2026-4619
GHSA-x9p5-w45c-7ffc
Mar 10, 2026
Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-25229
GO-2026-4499
GHSA-cv22-72px-f4gh
Feb 23, 2026
Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25232
GO-2026-4498
GHSA-2c6v-8r3v-gh6p
Feb 23, 2026
Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.1. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25120
GO-2026-4501
GHSA-jj5m-h57j-5gv7
Feb 23, 2026
Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25242
GO-2026-4500
GHSA-fc3h-92p8-h36f
Feb 23, 2026
Unauthenticated File Upload in Gogs in gogs.io/gogs Unauthenticated File Upload in Gogs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.1. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-23632
GO-2026-4450
GHSA-5qhx-gwfj-6jqr
Feb 17, 2026
Gogs user can update repository content with read-only permission in gogs.io/gogs Gogs user can update repository content with read-only permission in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4454
GHSA-26gq-grmh-6xm6
Feb 17, 2026
Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References
Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-64175
GO-2026-4449
GHSA-p6x6-9mx6-26wj
Feb 17, 2026
Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-23633
GO-2026-4453
GHSA-mrph-w4hh-gx3g
Feb 17, 2026
Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24135
GO-2026-4452
GHSA-jp7c-wj6q-3qf2
Feb 17, 2026
Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65852
GO-2026-4457
GHSA-rjv5-9px2-fqw6
Feb 17, 2026
Gogs has authorization bypass in repository deletion API in gogs.io/gogs Gogs has authorization bypass in repository deletion API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-64111
GO-2026-4448
GHSA-gg64-xxr9-qhjp
Feb 17, 2026
Gogs's update .git/config file allows remote command execution in gogs.io/gogs Gogs's update .git/config file allows remote command execution in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-22592
GO-2026-4451
GHSA-cr88-6mqm-4g57
Feb 17, 2026
Gogs has a Denial of Service issue in gogs.io/gogs Gogs has a Denial of Service issue in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References
Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-8110
GO-2025-4225
GHSA-mq8m-42gh-wq7r
Dec 15, 2025
Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-47943
GO-2025-3778
GHSA-xh32-cx6c-cp4v
Jul 28, 2025
Gogs XSS allowed by stored call in PDF renderer in gogs.io/gogs Gogs XSS allowed by stored call in PDF renderer in gogs.io/gogs Fixed in
0.13.3-0.20250608224432-110117b2e5e5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-56731
GO-2025-3776
GHSA-wj44-9vcg-wjq7
Jul 28, 2025
Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs Fixed in
0.13.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-44625
GO-2024-3275
GHSA-phm4-wf3h-pc3r
Nov 19, 2024
Unpatched Remote Code Execution in Gogs in gogs.io/gogs Unpatched Remote Code Execution in Gogs in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-32174
GO-2022-1060
GHSA-mcjj-2fvq-mc3r
Aug 21, 2024
Gogs vulnerable to Cross-site Scripting in gogs.io/gogs Gogs vulnerable to Cross-site Scripting in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev |
v0.13.2-rc.1
pre
Dependencies (57)
+ 49 more |
|
v0.13.2
patch
47 CVEs
CVE-2026-52802
GO-2026-5773
GHSA-xxhq-69mf-w8cr
Jun 25, 2026
Gogs has an Open Redirect via redirect_to in gogs.io/gogs Gogs has an Open Redirect via redirect_to in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52814
GO-2026-5765
GHSA-xp79-5mx3-jx52
Jun 25, 2026
Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52801
GO-2026-5724
GHSA-wv27-2vqp-j7g5
Jun 25, 2026
Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-25119
GO-2026-5695
GHSA-w6j9-vw59-27wv
Jun 25, 2026
Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52810
GO-2026-5712
GHSA-wmfg-5p4h-5fw3
Jun 25, 2026
Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52807
GO-2026-5661
GHSA-vcm5-gvmp-78mp
Jun 25, 2026
Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52799
GO-2026-5536
GHSA-p9f5-h3rx-j5qw
Jun 25, 2026
Gogs Missing Authorization in Attachment Download in gogs.io/gogs Gogs Missing Authorization in Attachment Download in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52797
GO-2026-5545
GHSA-pm6v-2h4w-4rp2
Jun 25, 2026
Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52806
GO-2026-5580
GHSA-qf6p-p7ww-cwr9
Jun 25, 2026
Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52800
GO-2026-5556
GHSA-pwx3-qcgw-vh7h
Jun 25, 2026
Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52808
GO-2026-5065
GHSA-268j-37xf-pp52
Jun 25, 2026
Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52798
GO-2026-5477
GHSA-jq8v-rmf6-65jw
Jun 25, 2026
Gogs has Stored XSS in `.ipynb` Preview in gogs.io/gogs Gogs has Stored XSS in NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52805
GO-2026-5387
GHSA-g2f5-gjr4-qjvm
Jun 25, 2026
Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47267
GO-2026-5312
GHSA-c4v7-xg93-qf8g
Jun 25, 2026
Gogs has SSRF in webhook deliveries in gogs.io/gogs Gogs has SSRF in webhook deliveries in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52813
GO-2026-5305
GHSA-c39w-43gm-34h5
Jun 25, 2026
Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5193
GHSA-6vxv-wg6j-5qwp
Jun 25, 2026
Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52815
GO-2026-5202
GHSA-744x-3838-5r56
Jun 25, 2026
Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52812
GO-2026-5184
GHSA-6p9m-q3jp-47h4
Jun 25, 2026
Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52811
GO-2026-5249
GHSA-89mr-xqfv-758m
Jun 25, 2026
Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-64719
GO-2026-5098
GHSA-3qq3-668m-v9mj
Jun 25, 2026
Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52816
GO-2026-5103
GHSA-3w28-36p9-w929
Jun 25, 2026
Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52809
GO-2026-5140
GHSA-5c3f-6486-3g7g
Jun 25, 2026
Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52804
GO-2026-5110
GHSA-4565-r4x7-hg8j
Jun 25, 2026
Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52796
GO-2026-5124
GHSA-4j89-2c4f-44c6
Jun 25, 2026
Gogs has DoS in rendering issue index pattern in gogs.io/gogs Gogs has DoS in rendering issue index pattern in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-25921
GO-2026-4616
GHSA-cj4v-437j-jq4c
Mar 10, 2026
Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26195
GO-2026-4618
GHSA-vgvf-m4fw-938j
Mar 10, 2026
Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26276
GO-2026-4627
GHSA-vgjm-2cpf-4g7c
Mar 10, 2026
Gogs: DOM-based XSS via milestone selection in gogs.io/gogs Gogs: DOM-based XSS via milestone selection in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26022
GO-2026-4620
GHSA-xrcr-gmf5-2r8j
Mar 10, 2026
Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26194
GO-2026-4617
GHSA-v9vm-r24h-6rqm
Mar 10, 2026
Gogs: Release tag option injection in release deletion in gogs.io/gogs Gogs: Release tag option injection in release deletion in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26196
GO-2026-4619
GHSA-x9p5-w45c-7ffc
Mar 10, 2026
Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-25229
GO-2026-4499
GHSA-cv22-72px-f4gh
Feb 23, 2026
Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25232
GO-2026-4498
GHSA-2c6v-8r3v-gh6p
Feb 23, 2026
Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.1. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25120
GO-2026-4501
GHSA-jj5m-h57j-5gv7
Feb 23, 2026
Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25242
GO-2026-4500
GHSA-fc3h-92p8-h36f
Feb 23, 2026
Unauthenticated File Upload in Gogs in gogs.io/gogs Unauthenticated File Upload in Gogs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.1. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-23632
GO-2026-4450
GHSA-5qhx-gwfj-6jqr
Feb 17, 2026
Gogs user can update repository content with read-only permission in gogs.io/gogs Gogs user can update repository content with read-only permission in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4454
GHSA-26gq-grmh-6xm6
Feb 17, 2026
Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References
Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-64175
GO-2026-4449
GHSA-p6x6-9mx6-26wj
Feb 17, 2026
Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-23633
GO-2026-4453
GHSA-mrph-w4hh-gx3g
Feb 17, 2026
Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24135
GO-2026-4452
GHSA-jp7c-wj6q-3qf2
Feb 17, 2026
Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65852
GO-2026-4457
GHSA-rjv5-9px2-fqw6
Feb 17, 2026
Gogs has authorization bypass in repository deletion API in gogs.io/gogs Gogs has authorization bypass in repository deletion API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-64111
GO-2026-4448
GHSA-gg64-xxr9-qhjp
Feb 17, 2026
Gogs's update .git/config file allows remote command execution in gogs.io/gogs Gogs's update .git/config file allows remote command execution in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-22592
GO-2026-4451
GHSA-cr88-6mqm-4g57
Feb 17, 2026
Gogs has a Denial of Service issue in gogs.io/gogs Gogs has a Denial of Service issue in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References
Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-8110
GO-2025-4225
GHSA-mq8m-42gh-wq7r
Dec 15, 2025
Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-47943
GO-2025-3778
GHSA-xh32-cx6c-cp4v
Jul 28, 2025
Gogs XSS allowed by stored call in PDF renderer in gogs.io/gogs Gogs XSS allowed by stored call in PDF renderer in gogs.io/gogs Fixed in
0.13.3-0.20250608224432-110117b2e5e5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-56731
GO-2025-3776
GHSA-wj44-9vcg-wjq7
Jul 28, 2025
Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs Fixed in
0.13.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-44625
GO-2024-3275
GHSA-phm4-wf3h-pc3r
Nov 19, 2024
Unpatched Remote Code Execution in Gogs in gogs.io/gogs Unpatched Remote Code Execution in Gogs in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-32174
GO-2022-1060
GHSA-mcjj-2fvq-mc3r
Aug 21, 2024
Gogs vulnerable to Cross-site Scripting in gogs.io/gogs Gogs vulnerable to Cross-site Scripting in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev |
v0.13.2
patch
Dependencies (57)
+ 49 more |
|
v0.13.1
patch
47 CVEs
CVE-2026-52802
GO-2026-5773
GHSA-xxhq-69mf-w8cr
Jun 25, 2026
Gogs has an Open Redirect via redirect_to in gogs.io/gogs Gogs has an Open Redirect via redirect_to in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52814
GO-2026-5765
GHSA-xp79-5mx3-jx52
Jun 25, 2026
Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52801
GO-2026-5724
GHSA-wv27-2vqp-j7g5
Jun 25, 2026
Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-25119
GO-2026-5695
GHSA-w6j9-vw59-27wv
Jun 25, 2026
Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52810
GO-2026-5712
GHSA-wmfg-5p4h-5fw3
Jun 25, 2026
Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52807
GO-2026-5661
GHSA-vcm5-gvmp-78mp
Jun 25, 2026
Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52799
GO-2026-5536
GHSA-p9f5-h3rx-j5qw
Jun 25, 2026
Gogs Missing Authorization in Attachment Download in gogs.io/gogs Gogs Missing Authorization in Attachment Download in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52797
GO-2026-5545
GHSA-pm6v-2h4w-4rp2
Jun 25, 2026
Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52806
GO-2026-5580
GHSA-qf6p-p7ww-cwr9
Jun 25, 2026
Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52800
GO-2026-5556
GHSA-pwx3-qcgw-vh7h
Jun 25, 2026
Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52808
GO-2026-5065
GHSA-268j-37xf-pp52
Jun 25, 2026
Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52798
GO-2026-5477
GHSA-jq8v-rmf6-65jw
Jun 25, 2026
Gogs has Stored XSS in `.ipynb` Preview in gogs.io/gogs Gogs has Stored XSS in NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52805
GO-2026-5387
GHSA-g2f5-gjr4-qjvm
Jun 25, 2026
Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47267
GO-2026-5312
GHSA-c4v7-xg93-qf8g
Jun 25, 2026
Gogs has SSRF in webhook deliveries in gogs.io/gogs Gogs has SSRF in webhook deliveries in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52813
GO-2026-5305
GHSA-c39w-43gm-34h5
Jun 25, 2026
Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5193
GHSA-6vxv-wg6j-5qwp
Jun 25, 2026
Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52815
GO-2026-5202
GHSA-744x-3838-5r56
Jun 25, 2026
Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52812
GO-2026-5184
GHSA-6p9m-q3jp-47h4
Jun 25, 2026
Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52811
GO-2026-5249
GHSA-89mr-xqfv-758m
Jun 25, 2026
Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-64719
GO-2026-5098
GHSA-3qq3-668m-v9mj
Jun 25, 2026
Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52816
GO-2026-5103
GHSA-3w28-36p9-w929
Jun 25, 2026
Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52809
GO-2026-5140
GHSA-5c3f-6486-3g7g
Jun 25, 2026
Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52804
GO-2026-5110
GHSA-4565-r4x7-hg8j
Jun 25, 2026
Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52796
GO-2026-5124
GHSA-4j89-2c4f-44c6
Jun 25, 2026
Gogs has DoS in rendering issue index pattern in gogs.io/gogs Gogs has DoS in rendering issue index pattern in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-25921
GO-2026-4616
GHSA-cj4v-437j-jq4c
Mar 10, 2026
Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26195
GO-2026-4618
GHSA-vgvf-m4fw-938j
Mar 10, 2026
Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26276
GO-2026-4627
GHSA-vgjm-2cpf-4g7c
Mar 10, 2026
Gogs: DOM-based XSS via milestone selection in gogs.io/gogs Gogs: DOM-based XSS via milestone selection in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26022
GO-2026-4620
GHSA-xrcr-gmf5-2r8j
Mar 10, 2026
Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26194
GO-2026-4617
GHSA-v9vm-r24h-6rqm
Mar 10, 2026
Gogs: Release tag option injection in release deletion in gogs.io/gogs Gogs: Release tag option injection in release deletion in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26196
GO-2026-4619
GHSA-x9p5-w45c-7ffc
Mar 10, 2026
Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-25229
GO-2026-4499
GHSA-cv22-72px-f4gh
Feb 23, 2026
Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25232
GO-2026-4498
GHSA-2c6v-8r3v-gh6p
Feb 23, 2026
Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.1. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25120
GO-2026-4501
GHSA-jj5m-h57j-5gv7
Feb 23, 2026
Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25242
GO-2026-4500
GHSA-fc3h-92p8-h36f
Feb 23, 2026
Unauthenticated File Upload in Gogs in gogs.io/gogs Unauthenticated File Upload in Gogs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.1. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-23632
GO-2026-4450
GHSA-5qhx-gwfj-6jqr
Feb 17, 2026
Gogs user can update repository content with read-only permission in gogs.io/gogs Gogs user can update repository content with read-only permission in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4454
GHSA-26gq-grmh-6xm6
Feb 17, 2026
Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References
Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-64175
GO-2026-4449
GHSA-p6x6-9mx6-26wj
Feb 17, 2026
Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-23633
GO-2026-4453
GHSA-mrph-w4hh-gx3g
Feb 17, 2026
Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24135
GO-2026-4452
GHSA-jp7c-wj6q-3qf2
Feb 17, 2026
Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65852
GO-2026-4457
GHSA-rjv5-9px2-fqw6
Feb 17, 2026
Gogs has authorization bypass in repository deletion API in gogs.io/gogs Gogs has authorization bypass in repository deletion API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-64111
GO-2026-4448
GHSA-gg64-xxr9-qhjp
Feb 17, 2026
Gogs's update .git/config file allows remote command execution in gogs.io/gogs Gogs's update .git/config file allows remote command execution in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-22592
GO-2026-4451
GHSA-cr88-6mqm-4g57
Feb 17, 2026
Gogs has a Denial of Service issue in gogs.io/gogs Gogs has a Denial of Service issue in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References
Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-8110
GO-2025-4225
GHSA-mq8m-42gh-wq7r
Dec 15, 2025
Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-47943
GO-2025-3778
GHSA-xh32-cx6c-cp4v
Jul 28, 2025
Gogs XSS allowed by stored call in PDF renderer in gogs.io/gogs Gogs XSS allowed by stored call in PDF renderer in gogs.io/gogs Fixed in
0.13.3-0.20250608224432-110117b2e5e5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-56731
GO-2025-3776
GHSA-wj44-9vcg-wjq7
Jul 28, 2025
Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs Fixed in
0.13.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-44625
GO-2024-3275
GHSA-phm4-wf3h-pc3r
Nov 19, 2024
Unpatched Remote Code Execution in Gogs in gogs.io/gogs Unpatched Remote Code Execution in Gogs in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-32174
GO-2022-1060
GHSA-mcjj-2fvq-mc3r
Aug 21, 2024
Gogs vulnerable to Cross-site Scripting in gogs.io/gogs Gogs vulnerable to Cross-site Scripting in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev |
v0.13.1
patch
Dependencies (57)
+ 49 more |
|
v0.13.1-rc.1
pre
53 CVEs
CVE-2026-52802
GO-2026-5773
GHSA-xxhq-69mf-w8cr
Jun 25, 2026
Gogs has an Open Redirect via redirect_to in gogs.io/gogs Gogs has an Open Redirect via redirect_to in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52814
GO-2026-5765
GHSA-xp79-5mx3-jx52
Jun 25, 2026
Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52801
GO-2026-5724
GHSA-wv27-2vqp-j7g5
Jun 25, 2026
Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-25119
GO-2026-5695
GHSA-w6j9-vw59-27wv
Jun 25, 2026
Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52810
GO-2026-5712
GHSA-wmfg-5p4h-5fw3
Jun 25, 2026
Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52807
GO-2026-5661
GHSA-vcm5-gvmp-78mp
Jun 25, 2026
Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52799
GO-2026-5536
GHSA-p9f5-h3rx-j5qw
Jun 25, 2026
Gogs Missing Authorization in Attachment Download in gogs.io/gogs Gogs Missing Authorization in Attachment Download in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52797
GO-2026-5545
GHSA-pm6v-2h4w-4rp2
Jun 25, 2026
Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52806
GO-2026-5580
GHSA-qf6p-p7ww-cwr9
Jun 25, 2026
Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52800
GO-2026-5556
GHSA-pwx3-qcgw-vh7h
Jun 25, 2026
Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52808
GO-2026-5065
GHSA-268j-37xf-pp52
Jun 25, 2026
Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52798
GO-2026-5477
GHSA-jq8v-rmf6-65jw
Jun 25, 2026
Gogs has Stored XSS in `.ipynb` Preview in gogs.io/gogs Gogs has Stored XSS in NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52805
GO-2026-5387
GHSA-g2f5-gjr4-qjvm
Jun 25, 2026
Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47267
GO-2026-5312
GHSA-c4v7-xg93-qf8g
Jun 25, 2026
Gogs has SSRF in webhook deliveries in gogs.io/gogs Gogs has SSRF in webhook deliveries in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52813
GO-2026-5305
GHSA-c39w-43gm-34h5
Jun 25, 2026
Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5193
GHSA-6vxv-wg6j-5qwp
Jun 25, 2026
Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52815
GO-2026-5202
GHSA-744x-3838-5r56
Jun 25, 2026
Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52812
GO-2026-5184
GHSA-6p9m-q3jp-47h4
Jun 25, 2026
Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52811
GO-2026-5249
GHSA-89mr-xqfv-758m
Jun 25, 2026
Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-64719
GO-2026-5098
GHSA-3qq3-668m-v9mj
Jun 25, 2026
Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52816
GO-2026-5103
GHSA-3w28-36p9-w929
Jun 25, 2026
Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52809
GO-2026-5140
GHSA-5c3f-6486-3g7g
Jun 25, 2026
Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52804
GO-2026-5110
GHSA-4565-r4x7-hg8j
Jun 25, 2026
Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52796
GO-2026-5124
GHSA-4j89-2c4f-44c6
Jun 25, 2026
Gogs has DoS in rendering issue index pattern in gogs.io/gogs Gogs has DoS in rendering issue index pattern in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-25921
GO-2026-4616
GHSA-cj4v-437j-jq4c
Mar 10, 2026
Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26195
GO-2026-4618
GHSA-vgvf-m4fw-938j
Mar 10, 2026
Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26276
GO-2026-4627
GHSA-vgjm-2cpf-4g7c
Mar 10, 2026
Gogs: DOM-based XSS via milestone selection in gogs.io/gogs Gogs: DOM-based XSS via milestone selection in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26022
GO-2026-4620
GHSA-xrcr-gmf5-2r8j
Mar 10, 2026
Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26194
GO-2026-4617
GHSA-v9vm-r24h-6rqm
Mar 10, 2026
Gogs: Release tag option injection in release deletion in gogs.io/gogs Gogs: Release tag option injection in release deletion in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26196
GO-2026-4619
GHSA-x9p5-w45c-7ffc
Mar 10, 2026
Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-25229
GO-2026-4499
GHSA-cv22-72px-f4gh
Feb 23, 2026
Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25232
GO-2026-4498
GHSA-2c6v-8r3v-gh6p
Feb 23, 2026
Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.1. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25120
GO-2026-4501
GHSA-jj5m-h57j-5gv7
Feb 23, 2026
Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25242
GO-2026-4500
GHSA-fc3h-92p8-h36f
Feb 23, 2026
Unauthenticated File Upload in Gogs in gogs.io/gogs Unauthenticated File Upload in Gogs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.1. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-23632
GO-2026-4450
GHSA-5qhx-gwfj-6jqr
Feb 17, 2026
Gogs user can update repository content with read-only permission in gogs.io/gogs Gogs user can update repository content with read-only permission in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4454
GHSA-26gq-grmh-6xm6
Feb 17, 2026
Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References
Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-64175
GO-2026-4449
GHSA-p6x6-9mx6-26wj
Feb 17, 2026
Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-23633
GO-2026-4453
GHSA-mrph-w4hh-gx3g
Feb 17, 2026
Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24135
GO-2026-4452
GHSA-jp7c-wj6q-3qf2
Feb 17, 2026
Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65852
GO-2026-4457
GHSA-rjv5-9px2-fqw6
Feb 17, 2026
Gogs has authorization bypass in repository deletion API in gogs.io/gogs Gogs has authorization bypass in repository deletion API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-64111
GO-2026-4448
GHSA-gg64-xxr9-qhjp
Feb 17, 2026
Gogs's update .git/config file allows remote command execution in gogs.io/gogs Gogs's update .git/config file allows remote command execution in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-22592
GO-2026-4451
GHSA-cr88-6mqm-4g57
Feb 17, 2026
Gogs has a Denial of Service issue in gogs.io/gogs Gogs has a Denial of Service issue in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References
Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-8110
GO-2025-4225
GHSA-mq8m-42gh-wq7r
Dec 15, 2025
Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-47943
GO-2025-3778
GHSA-xh32-cx6c-cp4v
Jul 28, 2025
Gogs XSS allowed by stored call in PDF renderer in gogs.io/gogs Gogs XSS allowed by stored call in PDF renderer in gogs.io/gogs Fixed in
0.13.3-0.20250608224432-110117b2e5e5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-56731
GO-2025-3776
GHSA-wj44-9vcg-wjq7
Jul 28, 2025
Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs Fixed in
0.13.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-55947
GO-2024-3356
GHSA-qf5v-rp47-55gg
Jan 07, 2025
Path Traversal in file update API in gogs in gogs.io/gogs Path Traversal in file update API in gogs in gogs.io/gogs Fixed in
0.13.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-54148
GO-2024-3355
GHSA-r7j8-5h9c-f6fx
Jan 07, 2025
Remote Command Execution in file editing in gogs in gogs.io/gogs Remote Command Execution in file editing in gogs in gogs.io/gogs Fixed in
0.13.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39930
GHSA-vm62-9jw3-c8w3
GHSA-p69r-v3h4-rj4f
GO-2024-2969
Dec 23, 2024
Gogs has an argument Injection in the built-in SSH server
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhen the built-in SSH server is enabled ( PatchesThe WorkaroundsDisable the use of built-in SSH server on operating systems other than Windows. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39930 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39932
GHSA-9pp6-wq8c-3w2c
GHSA-hf29-9hfh-w63j
GO-2024-2971
Dec 23, 2024
Gogs allows argument injection during the previewing of changes
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactUnprivileged user accounts can write to arbitrary files on the filesystem. We could demonstrate its exploitation to force a re-installation of the instance, granting administrator rights. It allows accessing and altering any user's code hosted on the same instance. PatchesUnintended Git options has been ignored for diff preview (https://github.com/gogs/gogs/pull/7871). Users should upgrade to 0.13.1 or the latest 0.14.0+dev. WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39932 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39931
GHSA-ccqv-43vm-4f3w
GHSA-2vgj-3pvg-xh4w
GO-2024-2970
Dec 23, 2024
Gogs allows deletion of internal files
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactUnprivileged user accounts can execute arbitrary commands on the Gogs instance with the privileges of the account specified by PatchesDeletion of WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39931 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39933
GHSA-m27m-h5gj-wwmg
GHSA-8mm6-wmpp-mmm3
GO-2024-2972
Dec 23, 2024
Gogs allows argument Injection when tagging new releases
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactUnprivileged user accounts with at least one SSH key can read arbitrary files on the system. For instance, they could leak the configuration files that could contain database credentials ( PatchesUnintended Git options has been ignored for creating tags (https://github.com/gogs/gogs/pull/7872). Users should upgrade to 0.13.1 or the latest 0.14.0+dev. WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39933 Fixed in
0.13.1
References
Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-44625
GO-2024-3275
GHSA-phm4-wf3h-pc3r
Nov 19, 2024
Unpatched Remote Code Execution in Gogs in gogs.io/gogs Unpatched Remote Code Execution in Gogs in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-32174
GO-2022-1060
GHSA-mcjj-2fvq-mc3r
Aug 21, 2024
Gogs vulnerable to Cross-site Scripting in gogs.io/gogs Gogs vulnerable to Cross-site Scripting in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev |
v0.13.1-rc.1
pre
Dependencies (57)
+ 49 more |
|
v0.13.0-rc.1
pre
53 CVEs
CVE-2026-52802
GO-2026-5773
GHSA-xxhq-69mf-w8cr
Jun 25, 2026
Gogs has an Open Redirect via redirect_to in gogs.io/gogs Gogs has an Open Redirect via redirect_to in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52814
GO-2026-5765
GHSA-xp79-5mx3-jx52
Jun 25, 2026
Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52801
GO-2026-5724
GHSA-wv27-2vqp-j7g5
Jun 25, 2026
Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-25119
GO-2026-5695
GHSA-w6j9-vw59-27wv
Jun 25, 2026
Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52810
GO-2026-5712
GHSA-wmfg-5p4h-5fw3
Jun 25, 2026
Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52807
GO-2026-5661
GHSA-vcm5-gvmp-78mp
Jun 25, 2026
Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52799
GO-2026-5536
GHSA-p9f5-h3rx-j5qw
Jun 25, 2026
Gogs Missing Authorization in Attachment Download in gogs.io/gogs Gogs Missing Authorization in Attachment Download in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52797
GO-2026-5545
GHSA-pm6v-2h4w-4rp2
Jun 25, 2026
Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52806
GO-2026-5580
GHSA-qf6p-p7ww-cwr9
Jun 25, 2026
Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52800
GO-2026-5556
GHSA-pwx3-qcgw-vh7h
Jun 25, 2026
Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52808
GO-2026-5065
GHSA-268j-37xf-pp52
Jun 25, 2026
Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52798
GO-2026-5477
GHSA-jq8v-rmf6-65jw
Jun 25, 2026
Gogs has Stored XSS in `.ipynb` Preview in gogs.io/gogs Gogs has Stored XSS in NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52805
GO-2026-5387
GHSA-g2f5-gjr4-qjvm
Jun 25, 2026
Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47267
GO-2026-5312
GHSA-c4v7-xg93-qf8g
Jun 25, 2026
Gogs has SSRF in webhook deliveries in gogs.io/gogs Gogs has SSRF in webhook deliveries in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52813
GO-2026-5305
GHSA-c39w-43gm-34h5
Jun 25, 2026
Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5193
GHSA-6vxv-wg6j-5qwp
Jun 25, 2026
Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52815
GO-2026-5202
GHSA-744x-3838-5r56
Jun 25, 2026
Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52812
GO-2026-5184
GHSA-6p9m-q3jp-47h4
Jun 25, 2026
Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52811
GO-2026-5249
GHSA-89mr-xqfv-758m
Jun 25, 2026
Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-64719
GO-2026-5098
GHSA-3qq3-668m-v9mj
Jun 25, 2026
Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52816
GO-2026-5103
GHSA-3w28-36p9-w929
Jun 25, 2026
Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52809
GO-2026-5140
GHSA-5c3f-6486-3g7g
Jun 25, 2026
Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52804
GO-2026-5110
GHSA-4565-r4x7-hg8j
Jun 25, 2026
Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52796
GO-2026-5124
GHSA-4j89-2c4f-44c6
Jun 25, 2026
Gogs has DoS in rendering issue index pattern in gogs.io/gogs Gogs has DoS in rendering issue index pattern in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-25921
GO-2026-4616
GHSA-cj4v-437j-jq4c
Mar 10, 2026
Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26195
GO-2026-4618
GHSA-vgvf-m4fw-938j
Mar 10, 2026
Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26276
GO-2026-4627
GHSA-vgjm-2cpf-4g7c
Mar 10, 2026
Gogs: DOM-based XSS via milestone selection in gogs.io/gogs Gogs: DOM-based XSS via milestone selection in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26022
GO-2026-4620
GHSA-xrcr-gmf5-2r8j
Mar 10, 2026
Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26194
GO-2026-4617
GHSA-v9vm-r24h-6rqm
Mar 10, 2026
Gogs: Release tag option injection in release deletion in gogs.io/gogs Gogs: Release tag option injection in release deletion in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26196
GO-2026-4619
GHSA-x9p5-w45c-7ffc
Mar 10, 2026
Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-25229
GO-2026-4499
GHSA-cv22-72px-f4gh
Feb 23, 2026
Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25232
GO-2026-4498
GHSA-2c6v-8r3v-gh6p
Feb 23, 2026
Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.1. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25120
GO-2026-4501
GHSA-jj5m-h57j-5gv7
Feb 23, 2026
Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25242
GO-2026-4500
GHSA-fc3h-92p8-h36f
Feb 23, 2026
Unauthenticated File Upload in Gogs in gogs.io/gogs Unauthenticated File Upload in Gogs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.1. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-23632
GO-2026-4450
GHSA-5qhx-gwfj-6jqr
Feb 17, 2026
Gogs user can update repository content with read-only permission in gogs.io/gogs Gogs user can update repository content with read-only permission in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4454
GHSA-26gq-grmh-6xm6
Feb 17, 2026
Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References
Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-64175
GO-2026-4449
GHSA-p6x6-9mx6-26wj
Feb 17, 2026
Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-23633
GO-2026-4453
GHSA-mrph-w4hh-gx3g
Feb 17, 2026
Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24135
GO-2026-4452
GHSA-jp7c-wj6q-3qf2
Feb 17, 2026
Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65852
GO-2026-4457
GHSA-rjv5-9px2-fqw6
Feb 17, 2026
Gogs has authorization bypass in repository deletion API in gogs.io/gogs Gogs has authorization bypass in repository deletion API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-64111
GO-2026-4448
GHSA-gg64-xxr9-qhjp
Feb 17, 2026
Gogs's update .git/config file allows remote command execution in gogs.io/gogs Gogs's update .git/config file allows remote command execution in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-22592
GO-2026-4451
GHSA-cr88-6mqm-4g57
Feb 17, 2026
Gogs has a Denial of Service issue in gogs.io/gogs Gogs has a Denial of Service issue in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References
Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-8110
GO-2025-4225
GHSA-mq8m-42gh-wq7r
Dec 15, 2025
Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-47943
GO-2025-3778
GHSA-xh32-cx6c-cp4v
Jul 28, 2025
Gogs XSS allowed by stored call in PDF renderer in gogs.io/gogs Gogs XSS allowed by stored call in PDF renderer in gogs.io/gogs Fixed in
0.13.3-0.20250608224432-110117b2e5e5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-56731
GO-2025-3776
GHSA-wj44-9vcg-wjq7
Jul 28, 2025
Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs Fixed in
0.13.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-55947
GO-2024-3356
GHSA-qf5v-rp47-55gg
Jan 07, 2025
Path Traversal in file update API in gogs in gogs.io/gogs Path Traversal in file update API in gogs in gogs.io/gogs Fixed in
0.13.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-54148
GO-2024-3355
GHSA-r7j8-5h9c-f6fx
Jan 07, 2025
Remote Command Execution in file editing in gogs in gogs.io/gogs Remote Command Execution in file editing in gogs in gogs.io/gogs Fixed in
0.13.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39930
GHSA-vm62-9jw3-c8w3
GHSA-p69r-v3h4-rj4f
GO-2024-2969
Dec 23, 2024
Gogs has an argument Injection in the built-in SSH server
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhen the built-in SSH server is enabled ( PatchesThe WorkaroundsDisable the use of built-in SSH server on operating systems other than Windows. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39930 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39932
GHSA-9pp6-wq8c-3w2c
GHSA-hf29-9hfh-w63j
GO-2024-2971
Dec 23, 2024
Gogs allows argument injection during the previewing of changes
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactUnprivileged user accounts can write to arbitrary files on the filesystem. We could demonstrate its exploitation to force a re-installation of the instance, granting administrator rights. It allows accessing and altering any user's code hosted on the same instance. PatchesUnintended Git options has been ignored for diff preview (https://github.com/gogs/gogs/pull/7871). Users should upgrade to 0.13.1 or the latest 0.14.0+dev. WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39932 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39931
GHSA-ccqv-43vm-4f3w
GHSA-2vgj-3pvg-xh4w
GO-2024-2970
Dec 23, 2024
Gogs allows deletion of internal files
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactUnprivileged user accounts can execute arbitrary commands on the Gogs instance with the privileges of the account specified by PatchesDeletion of WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39931 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39933
GHSA-m27m-h5gj-wwmg
GHSA-8mm6-wmpp-mmm3
GO-2024-2972
Dec 23, 2024
Gogs allows argument Injection when tagging new releases
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactUnprivileged user accounts with at least one SSH key can read arbitrary files on the system. For instance, they could leak the configuration files that could contain database credentials ( PatchesUnintended Git options has been ignored for creating tags (https://github.com/gogs/gogs/pull/7872). Users should upgrade to 0.13.1 or the latest 0.14.0+dev. WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39933 Fixed in
0.13.1
References
Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-44625
GO-2024-3275
GHSA-phm4-wf3h-pc3r
Nov 19, 2024
Unpatched Remote Code Execution in Gogs in gogs.io/gogs Unpatched Remote Code Execution in Gogs in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-32174
GO-2022-1060
GHSA-mcjj-2fvq-mc3r
Aug 21, 2024
Gogs vulnerable to Cross-site Scripting in gogs.io/gogs Gogs vulnerable to Cross-site Scripting in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev |
v0.13.0-rc.1
pre
Dependencies (57)
+ 49 more |
|
v0.13.0
minor
53 CVEs
CVE-2026-52802
GO-2026-5773
GHSA-xxhq-69mf-w8cr
Jun 25, 2026
Gogs has an Open Redirect via redirect_to in gogs.io/gogs Gogs has an Open Redirect via redirect_to in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52814
GO-2026-5765
GHSA-xp79-5mx3-jx52
Jun 25, 2026
Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52801
GO-2026-5724
GHSA-wv27-2vqp-j7g5
Jun 25, 2026
Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-25119
GO-2026-5695
GHSA-w6j9-vw59-27wv
Jun 25, 2026
Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52810
GO-2026-5712
GHSA-wmfg-5p4h-5fw3
Jun 25, 2026
Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52807
GO-2026-5661
GHSA-vcm5-gvmp-78mp
Jun 25, 2026
Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52799
GO-2026-5536
GHSA-p9f5-h3rx-j5qw
Jun 25, 2026
Gogs Missing Authorization in Attachment Download in gogs.io/gogs Gogs Missing Authorization in Attachment Download in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52797
GO-2026-5545
GHSA-pm6v-2h4w-4rp2
Jun 25, 2026
Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52806
GO-2026-5580
GHSA-qf6p-p7ww-cwr9
Jun 25, 2026
Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52800
GO-2026-5556
GHSA-pwx3-qcgw-vh7h
Jun 25, 2026
Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52808
GO-2026-5065
GHSA-268j-37xf-pp52
Jun 25, 2026
Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52798
GO-2026-5477
GHSA-jq8v-rmf6-65jw
Jun 25, 2026
Gogs has Stored XSS in `.ipynb` Preview in gogs.io/gogs Gogs has Stored XSS in NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52805
GO-2026-5387
GHSA-g2f5-gjr4-qjvm
Jun 25, 2026
Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47267
GO-2026-5312
GHSA-c4v7-xg93-qf8g
Jun 25, 2026
Gogs has SSRF in webhook deliveries in gogs.io/gogs Gogs has SSRF in webhook deliveries in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52813
GO-2026-5305
GHSA-c39w-43gm-34h5
Jun 25, 2026
Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5193
GHSA-6vxv-wg6j-5qwp
Jun 25, 2026
Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52815
GO-2026-5202
GHSA-744x-3838-5r56
Jun 25, 2026
Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52812
GO-2026-5184
GHSA-6p9m-q3jp-47h4
Jun 25, 2026
Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52811
GO-2026-5249
GHSA-89mr-xqfv-758m
Jun 25, 2026
Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-64719
GO-2026-5098
GHSA-3qq3-668m-v9mj
Jun 25, 2026
Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52816
GO-2026-5103
GHSA-3w28-36p9-w929
Jun 25, 2026
Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52809
GO-2026-5140
GHSA-5c3f-6486-3g7g
Jun 25, 2026
Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52804
GO-2026-5110
GHSA-4565-r4x7-hg8j
Jun 25, 2026
Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52796
GO-2026-5124
GHSA-4j89-2c4f-44c6
Jun 25, 2026
Gogs has DoS in rendering issue index pattern in gogs.io/gogs Gogs has DoS in rendering issue index pattern in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-25921
GO-2026-4616
GHSA-cj4v-437j-jq4c
Mar 10, 2026
Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26195
GO-2026-4618
GHSA-vgvf-m4fw-938j
Mar 10, 2026
Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26276
GO-2026-4627
GHSA-vgjm-2cpf-4g7c
Mar 10, 2026
Gogs: DOM-based XSS via milestone selection in gogs.io/gogs Gogs: DOM-based XSS via milestone selection in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26022
GO-2026-4620
GHSA-xrcr-gmf5-2r8j
Mar 10, 2026
Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26194
GO-2026-4617
GHSA-v9vm-r24h-6rqm
Mar 10, 2026
Gogs: Release tag option injection in release deletion in gogs.io/gogs Gogs: Release tag option injection in release deletion in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26196
GO-2026-4619
GHSA-x9p5-w45c-7ffc
Mar 10, 2026
Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-25229
GO-2026-4499
GHSA-cv22-72px-f4gh
Feb 23, 2026
Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25232
GO-2026-4498
GHSA-2c6v-8r3v-gh6p
Feb 23, 2026
Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.1. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25120
GO-2026-4501
GHSA-jj5m-h57j-5gv7
Feb 23, 2026
Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25242
GO-2026-4500
GHSA-fc3h-92p8-h36f
Feb 23, 2026
Unauthenticated File Upload in Gogs in gogs.io/gogs Unauthenticated File Upload in Gogs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.1. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-23632
GO-2026-4450
GHSA-5qhx-gwfj-6jqr
Feb 17, 2026
Gogs user can update repository content with read-only permission in gogs.io/gogs Gogs user can update repository content with read-only permission in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4454
GHSA-26gq-grmh-6xm6
Feb 17, 2026
Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References
Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-64175
GO-2026-4449
GHSA-p6x6-9mx6-26wj
Feb 17, 2026
Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-23633
GO-2026-4453
GHSA-mrph-w4hh-gx3g
Feb 17, 2026
Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24135
GO-2026-4452
GHSA-jp7c-wj6q-3qf2
Feb 17, 2026
Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65852
GO-2026-4457
GHSA-rjv5-9px2-fqw6
Feb 17, 2026
Gogs has authorization bypass in repository deletion API in gogs.io/gogs Gogs has authorization bypass in repository deletion API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-64111
GO-2026-4448
GHSA-gg64-xxr9-qhjp
Feb 17, 2026
Gogs's update .git/config file allows remote command execution in gogs.io/gogs Gogs's update .git/config file allows remote command execution in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-22592
GO-2026-4451
GHSA-cr88-6mqm-4g57
Feb 17, 2026
Gogs has a Denial of Service issue in gogs.io/gogs Gogs has a Denial of Service issue in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References
Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-8110
GO-2025-4225
GHSA-mq8m-42gh-wq7r
Dec 15, 2025
Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-47943
GO-2025-3778
GHSA-xh32-cx6c-cp4v
Jul 28, 2025
Gogs XSS allowed by stored call in PDF renderer in gogs.io/gogs Gogs XSS allowed by stored call in PDF renderer in gogs.io/gogs Fixed in
0.13.3-0.20250608224432-110117b2e5e5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-56731
GO-2025-3776
GHSA-wj44-9vcg-wjq7
Jul 28, 2025
Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs Fixed in
0.13.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-55947
GO-2024-3356
GHSA-qf5v-rp47-55gg
Jan 07, 2025
Path Traversal in file update API in gogs in gogs.io/gogs Path Traversal in file update API in gogs in gogs.io/gogs Fixed in
0.13.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-54148
GO-2024-3355
GHSA-r7j8-5h9c-f6fx
Jan 07, 2025
Remote Command Execution in file editing in gogs in gogs.io/gogs Remote Command Execution in file editing in gogs in gogs.io/gogs Fixed in
0.13.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39930
GHSA-vm62-9jw3-c8w3
GHSA-p69r-v3h4-rj4f
GO-2024-2969
Dec 23, 2024
Gogs has an argument Injection in the built-in SSH server
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhen the built-in SSH server is enabled ( PatchesThe WorkaroundsDisable the use of built-in SSH server on operating systems other than Windows. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39930 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39932
GHSA-9pp6-wq8c-3w2c
GHSA-hf29-9hfh-w63j
GO-2024-2971
Dec 23, 2024
Gogs allows argument injection during the previewing of changes
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactUnprivileged user accounts can write to arbitrary files on the filesystem. We could demonstrate its exploitation to force a re-installation of the instance, granting administrator rights. It allows accessing and altering any user's code hosted on the same instance. PatchesUnintended Git options has been ignored for diff preview (https://github.com/gogs/gogs/pull/7871). Users should upgrade to 0.13.1 or the latest 0.14.0+dev. WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39932 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39931
GHSA-ccqv-43vm-4f3w
GHSA-2vgj-3pvg-xh4w
GO-2024-2970
Dec 23, 2024
Gogs allows deletion of internal files
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactUnprivileged user accounts can execute arbitrary commands on the Gogs instance with the privileges of the account specified by PatchesDeletion of WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39931 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39933
GHSA-m27m-h5gj-wwmg
GHSA-8mm6-wmpp-mmm3
GO-2024-2972
Dec 23, 2024
Gogs allows argument Injection when tagging new releases
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactUnprivileged user accounts with at least one SSH key can read arbitrary files on the system. For instance, they could leak the configuration files that could contain database credentials ( PatchesUnintended Git options has been ignored for creating tags (https://github.com/gogs/gogs/pull/7872). Users should upgrade to 0.13.1 or the latest 0.14.0+dev. WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39933 Fixed in
0.13.1
References
Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-44625
GO-2024-3275
GHSA-phm4-wf3h-pc3r
Nov 19, 2024
Unpatched Remote Code Execution in Gogs in gogs.io/gogs Unpatched Remote Code Execution in Gogs in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-32174
GO-2022-1060
GHSA-mcjj-2fvq-mc3r
Aug 21, 2024
Gogs vulnerable to Cross-site Scripting in gogs.io/gogs Gogs vulnerable to Cross-site Scripting in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev |
v0.13.0
minor
Dependencies (57)
+ 49 more |
|
v0.12.11
patch
53 CVEs
CVE-2026-52802
GO-2026-5773
GHSA-xxhq-69mf-w8cr
Jun 25, 2026
Gogs has an Open Redirect via redirect_to in gogs.io/gogs Gogs has an Open Redirect via redirect_to in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52814
GO-2026-5765
GHSA-xp79-5mx3-jx52
Jun 25, 2026
Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52801
GO-2026-5724
GHSA-wv27-2vqp-j7g5
Jun 25, 2026
Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-25119
GO-2026-5695
GHSA-w6j9-vw59-27wv
Jun 25, 2026
Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52810
GO-2026-5712
GHSA-wmfg-5p4h-5fw3
Jun 25, 2026
Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52807
GO-2026-5661
GHSA-vcm5-gvmp-78mp
Jun 25, 2026
Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52799
GO-2026-5536
GHSA-p9f5-h3rx-j5qw
Jun 25, 2026
Gogs Missing Authorization in Attachment Download in gogs.io/gogs Gogs Missing Authorization in Attachment Download in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52797
GO-2026-5545
GHSA-pm6v-2h4w-4rp2
Jun 25, 2026
Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52806
GO-2026-5580
GHSA-qf6p-p7ww-cwr9
Jun 25, 2026
Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52800
GO-2026-5556
GHSA-pwx3-qcgw-vh7h
Jun 25, 2026
Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52808
GO-2026-5065
GHSA-268j-37xf-pp52
Jun 25, 2026
Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52798
GO-2026-5477
GHSA-jq8v-rmf6-65jw
Jun 25, 2026
Gogs has Stored XSS in `.ipynb` Preview in gogs.io/gogs Gogs has Stored XSS in NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52805
GO-2026-5387
GHSA-g2f5-gjr4-qjvm
Jun 25, 2026
Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47267
GO-2026-5312
GHSA-c4v7-xg93-qf8g
Jun 25, 2026
Gogs has SSRF in webhook deliveries in gogs.io/gogs Gogs has SSRF in webhook deliveries in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52813
GO-2026-5305
GHSA-c39w-43gm-34h5
Jun 25, 2026
Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5193
GHSA-6vxv-wg6j-5qwp
Jun 25, 2026
Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52815
GO-2026-5202
GHSA-744x-3838-5r56
Jun 25, 2026
Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52812
GO-2026-5184
GHSA-6p9m-q3jp-47h4
Jun 25, 2026
Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52811
GO-2026-5249
GHSA-89mr-xqfv-758m
Jun 25, 2026
Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-64719
GO-2026-5098
GHSA-3qq3-668m-v9mj
Jun 25, 2026
Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52816
GO-2026-5103
GHSA-3w28-36p9-w929
Jun 25, 2026
Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52809
GO-2026-5140
GHSA-5c3f-6486-3g7g
Jun 25, 2026
Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52804
GO-2026-5110
GHSA-4565-r4x7-hg8j
Jun 25, 2026
Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52796
GO-2026-5124
GHSA-4j89-2c4f-44c6
Jun 25, 2026
Gogs has DoS in rendering issue index pattern in gogs.io/gogs Gogs has DoS in rendering issue index pattern in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-25921
GO-2026-4616
GHSA-cj4v-437j-jq4c
Mar 10, 2026
Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26195
GO-2026-4618
GHSA-vgvf-m4fw-938j
Mar 10, 2026
Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26276
GO-2026-4627
GHSA-vgjm-2cpf-4g7c
Mar 10, 2026
Gogs: DOM-based XSS via milestone selection in gogs.io/gogs Gogs: DOM-based XSS via milestone selection in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26022
GO-2026-4620
GHSA-xrcr-gmf5-2r8j
Mar 10, 2026
Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26194
GO-2026-4617
GHSA-v9vm-r24h-6rqm
Mar 10, 2026
Gogs: Release tag option injection in release deletion in gogs.io/gogs Gogs: Release tag option injection in release deletion in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26196
GO-2026-4619
GHSA-x9p5-w45c-7ffc
Mar 10, 2026
Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-25229
GO-2026-4499
GHSA-cv22-72px-f4gh
Feb 23, 2026
Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25232
GO-2026-4498
GHSA-2c6v-8r3v-gh6p
Feb 23, 2026
Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.1. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25120
GO-2026-4501
GHSA-jj5m-h57j-5gv7
Feb 23, 2026
Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25242
GO-2026-4500
GHSA-fc3h-92p8-h36f
Feb 23, 2026
Unauthenticated File Upload in Gogs in gogs.io/gogs Unauthenticated File Upload in Gogs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.1. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-23632
GO-2026-4450
GHSA-5qhx-gwfj-6jqr
Feb 17, 2026
Gogs user can update repository content with read-only permission in gogs.io/gogs Gogs user can update repository content with read-only permission in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4454
GHSA-26gq-grmh-6xm6
Feb 17, 2026
Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References
Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-64175
GO-2026-4449
GHSA-p6x6-9mx6-26wj
Feb 17, 2026
Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-23633
GO-2026-4453
GHSA-mrph-w4hh-gx3g
Feb 17, 2026
Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24135
GO-2026-4452
GHSA-jp7c-wj6q-3qf2
Feb 17, 2026
Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65852
GO-2026-4457
GHSA-rjv5-9px2-fqw6
Feb 17, 2026
Gogs has authorization bypass in repository deletion API in gogs.io/gogs Gogs has authorization bypass in repository deletion API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-64111
GO-2026-4448
GHSA-gg64-xxr9-qhjp
Feb 17, 2026
Gogs's update .git/config file allows remote command execution in gogs.io/gogs Gogs's update .git/config file allows remote command execution in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-22592
GO-2026-4451
GHSA-cr88-6mqm-4g57
Feb 17, 2026
Gogs has a Denial of Service issue in gogs.io/gogs Gogs has a Denial of Service issue in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References
Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-8110
GO-2025-4225
GHSA-mq8m-42gh-wq7r
Dec 15, 2025
Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-47943
GO-2025-3778
GHSA-xh32-cx6c-cp4v
Jul 28, 2025
Gogs XSS allowed by stored call in PDF renderer in gogs.io/gogs Gogs XSS allowed by stored call in PDF renderer in gogs.io/gogs Fixed in
0.13.3-0.20250608224432-110117b2e5e5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-56731
GO-2025-3776
GHSA-wj44-9vcg-wjq7
Jul 28, 2025
Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs Fixed in
0.13.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-55947
GO-2024-3356
GHSA-qf5v-rp47-55gg
Jan 07, 2025
Path Traversal in file update API in gogs in gogs.io/gogs Path Traversal in file update API in gogs in gogs.io/gogs Fixed in
0.13.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-54148
GO-2024-3355
GHSA-r7j8-5h9c-f6fx
Jan 07, 2025
Remote Command Execution in file editing in gogs in gogs.io/gogs Remote Command Execution in file editing in gogs in gogs.io/gogs Fixed in
0.13.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39930
GHSA-vm62-9jw3-c8w3
GHSA-p69r-v3h4-rj4f
GO-2024-2969
Dec 23, 2024
Gogs has an argument Injection in the built-in SSH server
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhen the built-in SSH server is enabled ( PatchesThe WorkaroundsDisable the use of built-in SSH server on operating systems other than Windows. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39930 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39932
GHSA-9pp6-wq8c-3w2c
GHSA-hf29-9hfh-w63j
GO-2024-2971
Dec 23, 2024
Gogs allows argument injection during the previewing of changes
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactUnprivileged user accounts can write to arbitrary files on the filesystem. We could demonstrate its exploitation to force a re-installation of the instance, granting administrator rights. It allows accessing and altering any user's code hosted on the same instance. PatchesUnintended Git options has been ignored for diff preview (https://github.com/gogs/gogs/pull/7871). Users should upgrade to 0.13.1 or the latest 0.14.0+dev. WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39932 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39931
GHSA-ccqv-43vm-4f3w
GHSA-2vgj-3pvg-xh4w
GO-2024-2970
Dec 23, 2024
Gogs allows deletion of internal files
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactUnprivileged user accounts can execute arbitrary commands on the Gogs instance with the privileges of the account specified by PatchesDeletion of WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39931 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39933
GHSA-m27m-h5gj-wwmg
GHSA-8mm6-wmpp-mmm3
GO-2024-2972
Dec 23, 2024
Gogs allows argument Injection when tagging new releases
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactUnprivileged user accounts with at least one SSH key can read arbitrary files on the system. For instance, they could leak the configuration files that could contain database credentials ( PatchesUnintended Git options has been ignored for creating tags (https://github.com/gogs/gogs/pull/7872). Users should upgrade to 0.13.1 or the latest 0.14.0+dev. WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39933 Fixed in
0.13.1
References
Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-44625
GO-2024-3275
GHSA-phm4-wf3h-pc3r
Nov 19, 2024
Unpatched Remote Code Execution in Gogs in gogs.io/gogs Unpatched Remote Code Execution in Gogs in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-32174
GO-2022-1060
GHSA-mcjj-2fvq-mc3r
Aug 21, 2024
Gogs vulnerable to Cross-site Scripting in gogs.io/gogs Gogs vulnerable to Cross-site Scripting in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev |
v0.12.11
patch
Dependencies (49)
+ 41 more |
|
v0.12.11-rc.1
pre
54 CVEs
CVE-2026-52802
GO-2026-5773
GHSA-xxhq-69mf-w8cr
Jun 25, 2026
Gogs has an Open Redirect via redirect_to in gogs.io/gogs Gogs has an Open Redirect via redirect_to in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52814
GO-2026-5765
GHSA-xp79-5mx3-jx52
Jun 25, 2026
Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52801
GO-2026-5724
GHSA-wv27-2vqp-j7g5
Jun 25, 2026
Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-25119
GO-2026-5695
GHSA-w6j9-vw59-27wv
Jun 25, 2026
Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52810
GO-2026-5712
GHSA-wmfg-5p4h-5fw3
Jun 25, 2026
Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52807
GO-2026-5661
GHSA-vcm5-gvmp-78mp
Jun 25, 2026
Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52799
GO-2026-5536
GHSA-p9f5-h3rx-j5qw
Jun 25, 2026
Gogs Missing Authorization in Attachment Download in gogs.io/gogs Gogs Missing Authorization in Attachment Download in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52797
GO-2026-5545
GHSA-pm6v-2h4w-4rp2
Jun 25, 2026
Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52806
GO-2026-5580
GHSA-qf6p-p7ww-cwr9
Jun 25, 2026
Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52800
GO-2026-5556
GHSA-pwx3-qcgw-vh7h
Jun 25, 2026
Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52808
GO-2026-5065
GHSA-268j-37xf-pp52
Jun 25, 2026
Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52798
GO-2026-5477
GHSA-jq8v-rmf6-65jw
Jun 25, 2026
Gogs has Stored XSS in `.ipynb` Preview in gogs.io/gogs Gogs has Stored XSS in NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52805
GO-2026-5387
GHSA-g2f5-gjr4-qjvm
Jun 25, 2026
Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47267
GO-2026-5312
GHSA-c4v7-xg93-qf8g
Jun 25, 2026
Gogs has SSRF in webhook deliveries in gogs.io/gogs Gogs has SSRF in webhook deliveries in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52813
GO-2026-5305
GHSA-c39w-43gm-34h5
Jun 25, 2026
Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5193
GHSA-6vxv-wg6j-5qwp
Jun 25, 2026
Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52815
GO-2026-5202
GHSA-744x-3838-5r56
Jun 25, 2026
Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52812
GO-2026-5184
GHSA-6p9m-q3jp-47h4
Jun 25, 2026
Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52811
GO-2026-5249
GHSA-89mr-xqfv-758m
Jun 25, 2026
Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-64719
GO-2026-5098
GHSA-3qq3-668m-v9mj
Jun 25, 2026
Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52816
GO-2026-5103
GHSA-3w28-36p9-w929
Jun 25, 2026
Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52809
GO-2026-5140
GHSA-5c3f-6486-3g7g
Jun 25, 2026
Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52804
GO-2026-5110
GHSA-4565-r4x7-hg8j
Jun 25, 2026
Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52796
GO-2026-5124
GHSA-4j89-2c4f-44c6
Jun 25, 2026
Gogs has DoS in rendering issue index pattern in gogs.io/gogs Gogs has DoS in rendering issue index pattern in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-25921
GO-2026-4616
GHSA-cj4v-437j-jq4c
Mar 10, 2026
Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26195
GO-2026-4618
GHSA-vgvf-m4fw-938j
Mar 10, 2026
Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26276
GO-2026-4627
GHSA-vgjm-2cpf-4g7c
Mar 10, 2026
Gogs: DOM-based XSS via milestone selection in gogs.io/gogs Gogs: DOM-based XSS via milestone selection in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26022
GO-2026-4620
GHSA-xrcr-gmf5-2r8j
Mar 10, 2026
Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26194
GO-2026-4617
GHSA-v9vm-r24h-6rqm
Mar 10, 2026
Gogs: Release tag option injection in release deletion in gogs.io/gogs Gogs: Release tag option injection in release deletion in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26196
GO-2026-4619
GHSA-x9p5-w45c-7ffc
Mar 10, 2026
Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-25229
GO-2026-4499
GHSA-cv22-72px-f4gh
Feb 23, 2026
Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25232
GO-2026-4498
GHSA-2c6v-8r3v-gh6p
Feb 23, 2026
Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.1. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25120
GO-2026-4501
GHSA-jj5m-h57j-5gv7
Feb 23, 2026
Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25242
GO-2026-4500
GHSA-fc3h-92p8-h36f
Feb 23, 2026
Unauthenticated File Upload in Gogs in gogs.io/gogs Unauthenticated File Upload in Gogs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.1. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-23632
GO-2026-4450
GHSA-5qhx-gwfj-6jqr
Feb 17, 2026
Gogs user can update repository content with read-only permission in gogs.io/gogs Gogs user can update repository content with read-only permission in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4454
GHSA-26gq-grmh-6xm6
Feb 17, 2026
Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References
Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-64175
GO-2026-4449
GHSA-p6x6-9mx6-26wj
Feb 17, 2026
Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-23633
GO-2026-4453
GHSA-mrph-w4hh-gx3g
Feb 17, 2026
Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24135
GO-2026-4452
GHSA-jp7c-wj6q-3qf2
Feb 17, 2026
Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65852
GO-2026-4457
GHSA-rjv5-9px2-fqw6
Feb 17, 2026
Gogs has authorization bypass in repository deletion API in gogs.io/gogs Gogs has authorization bypass in repository deletion API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-64111
GO-2026-4448
GHSA-gg64-xxr9-qhjp
Feb 17, 2026
Gogs's update .git/config file allows remote command execution in gogs.io/gogs Gogs's update .git/config file allows remote command execution in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-22592
GO-2026-4451
GHSA-cr88-6mqm-4g57
Feb 17, 2026
Gogs has a Denial of Service issue in gogs.io/gogs Gogs has a Denial of Service issue in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References
Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-8110
GO-2025-4225
GHSA-mq8m-42gh-wq7r
Dec 15, 2025
Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-47943
GO-2025-3778
GHSA-xh32-cx6c-cp4v
Jul 28, 2025
Gogs XSS allowed by stored call in PDF renderer in gogs.io/gogs Gogs XSS allowed by stored call in PDF renderer in gogs.io/gogs Fixed in
0.13.3-0.20250608224432-110117b2e5e5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-56731
GO-2025-3776
GHSA-wj44-9vcg-wjq7
Jul 28, 2025
Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs Fixed in
0.13.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-55947
GO-2024-3356
GHSA-qf5v-rp47-55gg
Jan 07, 2025
Path Traversal in file update API in gogs in gogs.io/gogs Path Traversal in file update API in gogs in gogs.io/gogs Fixed in
0.13.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-54148
GO-2024-3355
GHSA-r7j8-5h9c-f6fx
Jan 07, 2025
Remote Command Execution in file editing in gogs in gogs.io/gogs Remote Command Execution in file editing in gogs in gogs.io/gogs Fixed in
0.13.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39930
GHSA-vm62-9jw3-c8w3
GHSA-p69r-v3h4-rj4f
GO-2024-2969
Dec 23, 2024
Gogs has an argument Injection in the built-in SSH server
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhen the built-in SSH server is enabled ( PatchesThe WorkaroundsDisable the use of built-in SSH server on operating systems other than Windows. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39930 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39932
GHSA-9pp6-wq8c-3w2c
GHSA-hf29-9hfh-w63j
GO-2024-2971
Dec 23, 2024
Gogs allows argument injection during the previewing of changes
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactUnprivileged user accounts can write to arbitrary files on the filesystem. We could demonstrate its exploitation to force a re-installation of the instance, granting administrator rights. It allows accessing and altering any user's code hosted on the same instance. PatchesUnintended Git options has been ignored for diff preview (https://github.com/gogs/gogs/pull/7871). Users should upgrade to 0.13.1 or the latest 0.14.0+dev. WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39932 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39931
GHSA-ccqv-43vm-4f3w
GHSA-2vgj-3pvg-xh4w
GO-2024-2970
Dec 23, 2024
Gogs allows deletion of internal files
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactUnprivileged user accounts can execute arbitrary commands on the Gogs instance with the privileges of the account specified by PatchesDeletion of WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39931 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39933
GHSA-m27m-h5gj-wwmg
GHSA-8mm6-wmpp-mmm3
GO-2024-2972
Dec 23, 2024
Gogs allows argument Injection when tagging new releases
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactUnprivileged user accounts with at least one SSH key can read arbitrary files on the system. For instance, they could leak the configuration files that could contain database credentials ( PatchesUnintended Git options has been ignored for creating tags (https://github.com/gogs/gogs/pull/7872). Users should upgrade to 0.13.1 or the latest 0.14.0+dev. WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39933 Fixed in
0.13.1
References
Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-44625
GO-2024-3275
GHSA-phm4-wf3h-pc3r
Nov 19, 2024
Unpatched Remote Code Execution in Gogs in gogs.io/gogs Unpatched Remote Code Execution in Gogs in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-32174
GO-2022-1060
GHSA-mcjj-2fvq-mc3r
Aug 21, 2024
Gogs vulnerable to Cross-site Scripting in gogs.io/gogs Gogs vulnerable to Cross-site Scripting in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2024
GO-2023-1596
GHSA-pfvh-p8qp-9ww9
Aug 20, 2024
Gogs OS Command Injection vulnerability in gogs.io/gogs Gogs OS Command Injection vulnerability in gogs.io/gogs Fixed in
0.12.11
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.12.11-rc.1
pre
Dependencies (49)
+ 41 more |
|
v0.12.10
patch
54 CVEs
CVE-2026-52802
GO-2026-5773
GHSA-xxhq-69mf-w8cr
Jun 25, 2026
Gogs has an Open Redirect via redirect_to in gogs.io/gogs Gogs has an Open Redirect via redirect_to in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52814
GO-2026-5765
GHSA-xp79-5mx3-jx52
Jun 25, 2026
Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52801
GO-2026-5724
GHSA-wv27-2vqp-j7g5
Jun 25, 2026
Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-25119
GO-2026-5695
GHSA-w6j9-vw59-27wv
Jun 25, 2026
Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52810
GO-2026-5712
GHSA-wmfg-5p4h-5fw3
Jun 25, 2026
Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52807
GO-2026-5661
GHSA-vcm5-gvmp-78mp
Jun 25, 2026
Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52799
GO-2026-5536
GHSA-p9f5-h3rx-j5qw
Jun 25, 2026
Gogs Missing Authorization in Attachment Download in gogs.io/gogs Gogs Missing Authorization in Attachment Download in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52797
GO-2026-5545
GHSA-pm6v-2h4w-4rp2
Jun 25, 2026
Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52806
GO-2026-5580
GHSA-qf6p-p7ww-cwr9
Jun 25, 2026
Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52800
GO-2026-5556
GHSA-pwx3-qcgw-vh7h
Jun 25, 2026
Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52808
GO-2026-5065
GHSA-268j-37xf-pp52
Jun 25, 2026
Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52798
GO-2026-5477
GHSA-jq8v-rmf6-65jw
Jun 25, 2026
Gogs has Stored XSS in `.ipynb` Preview in gogs.io/gogs Gogs has Stored XSS in NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52805
GO-2026-5387
GHSA-g2f5-gjr4-qjvm
Jun 25, 2026
Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47267
GO-2026-5312
GHSA-c4v7-xg93-qf8g
Jun 25, 2026
Gogs has SSRF in webhook deliveries in gogs.io/gogs Gogs has SSRF in webhook deliveries in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52813
GO-2026-5305
GHSA-c39w-43gm-34h5
Jun 25, 2026
Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5193
GHSA-6vxv-wg6j-5qwp
Jun 25, 2026
Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52815
GO-2026-5202
GHSA-744x-3838-5r56
Jun 25, 2026
Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52812
GO-2026-5184
GHSA-6p9m-q3jp-47h4
Jun 25, 2026
Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52811
GO-2026-5249
GHSA-89mr-xqfv-758m
Jun 25, 2026
Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-64719
GO-2026-5098
GHSA-3qq3-668m-v9mj
Jun 25, 2026
Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52816
GO-2026-5103
GHSA-3w28-36p9-w929
Jun 25, 2026
Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52809
GO-2026-5140
GHSA-5c3f-6486-3g7g
Jun 25, 2026
Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52804
GO-2026-5110
GHSA-4565-r4x7-hg8j
Jun 25, 2026
Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52796
GO-2026-5124
GHSA-4j89-2c4f-44c6
Jun 25, 2026
Gogs has DoS in rendering issue index pattern in gogs.io/gogs Gogs has DoS in rendering issue index pattern in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-25921
GO-2026-4616
GHSA-cj4v-437j-jq4c
Mar 10, 2026
Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26195
GO-2026-4618
GHSA-vgvf-m4fw-938j
Mar 10, 2026
Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26276
GO-2026-4627
GHSA-vgjm-2cpf-4g7c
Mar 10, 2026
Gogs: DOM-based XSS via milestone selection in gogs.io/gogs Gogs: DOM-based XSS via milestone selection in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26022
GO-2026-4620
GHSA-xrcr-gmf5-2r8j
Mar 10, 2026
Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26194
GO-2026-4617
GHSA-v9vm-r24h-6rqm
Mar 10, 2026
Gogs: Release tag option injection in release deletion in gogs.io/gogs Gogs: Release tag option injection in release deletion in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26196
GO-2026-4619
GHSA-x9p5-w45c-7ffc
Mar 10, 2026
Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-25229
GO-2026-4499
GHSA-cv22-72px-f4gh
Feb 23, 2026
Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25232
GO-2026-4498
GHSA-2c6v-8r3v-gh6p
Feb 23, 2026
Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.1. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25120
GO-2026-4501
GHSA-jj5m-h57j-5gv7
Feb 23, 2026
Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25242
GO-2026-4500
GHSA-fc3h-92p8-h36f
Feb 23, 2026
Unauthenticated File Upload in Gogs in gogs.io/gogs Unauthenticated File Upload in Gogs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.1. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-23632
GO-2026-4450
GHSA-5qhx-gwfj-6jqr
Feb 17, 2026
Gogs user can update repository content with read-only permission in gogs.io/gogs Gogs user can update repository content with read-only permission in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4454
GHSA-26gq-grmh-6xm6
Feb 17, 2026
Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References
Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-64175
GO-2026-4449
GHSA-p6x6-9mx6-26wj
Feb 17, 2026
Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-23633
GO-2026-4453
GHSA-mrph-w4hh-gx3g
Feb 17, 2026
Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24135
GO-2026-4452
GHSA-jp7c-wj6q-3qf2
Feb 17, 2026
Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65852
GO-2026-4457
GHSA-rjv5-9px2-fqw6
Feb 17, 2026
Gogs has authorization bypass in repository deletion API in gogs.io/gogs Gogs has authorization bypass in repository deletion API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-64111
GO-2026-4448
GHSA-gg64-xxr9-qhjp
Feb 17, 2026
Gogs's update .git/config file allows remote command execution in gogs.io/gogs Gogs's update .git/config file allows remote command execution in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-22592
GO-2026-4451
GHSA-cr88-6mqm-4g57
Feb 17, 2026
Gogs has a Denial of Service issue in gogs.io/gogs Gogs has a Denial of Service issue in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References
Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-8110
GO-2025-4225
GHSA-mq8m-42gh-wq7r
Dec 15, 2025
Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-47943
GO-2025-3778
GHSA-xh32-cx6c-cp4v
Jul 28, 2025
Gogs XSS allowed by stored call in PDF renderer in gogs.io/gogs Gogs XSS allowed by stored call in PDF renderer in gogs.io/gogs Fixed in
0.13.3-0.20250608224432-110117b2e5e5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-56731
GO-2025-3776
GHSA-wj44-9vcg-wjq7
Jul 28, 2025
Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs Fixed in
0.13.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-55947
GO-2024-3356
GHSA-qf5v-rp47-55gg
Jan 07, 2025
Path Traversal in file update API in gogs in gogs.io/gogs Path Traversal in file update API in gogs in gogs.io/gogs Fixed in
0.13.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-54148
GO-2024-3355
GHSA-r7j8-5h9c-f6fx
Jan 07, 2025
Remote Command Execution in file editing in gogs in gogs.io/gogs Remote Command Execution in file editing in gogs in gogs.io/gogs Fixed in
0.13.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39930
GHSA-vm62-9jw3-c8w3
GHSA-p69r-v3h4-rj4f
GO-2024-2969
Dec 23, 2024
Gogs has an argument Injection in the built-in SSH server
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhen the built-in SSH server is enabled ( PatchesThe WorkaroundsDisable the use of built-in SSH server on operating systems other than Windows. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39930 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39932
GHSA-9pp6-wq8c-3w2c
GHSA-hf29-9hfh-w63j
GO-2024-2971
Dec 23, 2024
Gogs allows argument injection during the previewing of changes
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactUnprivileged user accounts can write to arbitrary files on the filesystem. We could demonstrate its exploitation to force a re-installation of the instance, granting administrator rights. It allows accessing and altering any user's code hosted on the same instance. PatchesUnintended Git options has been ignored for diff preview (https://github.com/gogs/gogs/pull/7871). Users should upgrade to 0.13.1 or the latest 0.14.0+dev. WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39932 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39931
GHSA-ccqv-43vm-4f3w
GHSA-2vgj-3pvg-xh4w
GO-2024-2970
Dec 23, 2024
Gogs allows deletion of internal files
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactUnprivileged user accounts can execute arbitrary commands on the Gogs instance with the privileges of the account specified by PatchesDeletion of WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39931 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39933
GHSA-m27m-h5gj-wwmg
GHSA-8mm6-wmpp-mmm3
GO-2024-2972
Dec 23, 2024
Gogs allows argument Injection when tagging new releases
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactUnprivileged user accounts with at least one SSH key can read arbitrary files on the system. For instance, they could leak the configuration files that could contain database credentials ( PatchesUnintended Git options has been ignored for creating tags (https://github.com/gogs/gogs/pull/7872). Users should upgrade to 0.13.1 or the latest 0.14.0+dev. WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39933 Fixed in
0.13.1
References
Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-44625
GO-2024-3275
GHSA-phm4-wf3h-pc3r
Nov 19, 2024
Unpatched Remote Code Execution in Gogs in gogs.io/gogs Unpatched Remote Code Execution in Gogs in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-32174
GO-2022-1060
GHSA-mcjj-2fvq-mc3r
Aug 21, 2024
Gogs vulnerable to Cross-site Scripting in gogs.io/gogs Gogs vulnerable to Cross-site Scripting in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2024
GO-2023-1596
GHSA-pfvh-p8qp-9ww9
Aug 20, 2024
Gogs OS Command Injection vulnerability in gogs.io/gogs Gogs OS Command Injection vulnerability in gogs.io/gogs Fixed in
0.12.11
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.12.10
patch
Dependencies (49)
+ 41 more |
|
v0.12.10-rc.1
pre
54 CVEs
CVE-2026-52802
GO-2026-5773
GHSA-xxhq-69mf-w8cr
Jun 25, 2026
Gogs has an Open Redirect via redirect_to in gogs.io/gogs Gogs has an Open Redirect via redirect_to in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52814
GO-2026-5765
GHSA-xp79-5mx3-jx52
Jun 25, 2026
Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52801
GO-2026-5724
GHSA-wv27-2vqp-j7g5
Jun 25, 2026
Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-25119
GO-2026-5695
GHSA-w6j9-vw59-27wv
Jun 25, 2026
Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52810
GO-2026-5712
GHSA-wmfg-5p4h-5fw3
Jun 25, 2026
Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52807
GO-2026-5661
GHSA-vcm5-gvmp-78mp
Jun 25, 2026
Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52799
GO-2026-5536
GHSA-p9f5-h3rx-j5qw
Jun 25, 2026
Gogs Missing Authorization in Attachment Download in gogs.io/gogs Gogs Missing Authorization in Attachment Download in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52797
GO-2026-5545
GHSA-pm6v-2h4w-4rp2
Jun 25, 2026
Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52806
GO-2026-5580
GHSA-qf6p-p7ww-cwr9
Jun 25, 2026
Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52800
GO-2026-5556
GHSA-pwx3-qcgw-vh7h
Jun 25, 2026
Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52808
GO-2026-5065
GHSA-268j-37xf-pp52
Jun 25, 2026
Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52798
GO-2026-5477
GHSA-jq8v-rmf6-65jw
Jun 25, 2026
Gogs has Stored XSS in `.ipynb` Preview in gogs.io/gogs Gogs has Stored XSS in NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52805
GO-2026-5387
GHSA-g2f5-gjr4-qjvm
Jun 25, 2026
Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47267
GO-2026-5312
GHSA-c4v7-xg93-qf8g
Jun 25, 2026
Gogs has SSRF in webhook deliveries in gogs.io/gogs Gogs has SSRF in webhook deliveries in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52813
GO-2026-5305
GHSA-c39w-43gm-34h5
Jun 25, 2026
Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5193
GHSA-6vxv-wg6j-5qwp
Jun 25, 2026
Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52815
GO-2026-5202
GHSA-744x-3838-5r56
Jun 25, 2026
Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52812
GO-2026-5184
GHSA-6p9m-q3jp-47h4
Jun 25, 2026
Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52811
GO-2026-5249
GHSA-89mr-xqfv-758m
Jun 25, 2026
Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-64719
GO-2026-5098
GHSA-3qq3-668m-v9mj
Jun 25, 2026
Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52816
GO-2026-5103
GHSA-3w28-36p9-w929
Jun 25, 2026
Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52809
GO-2026-5140
GHSA-5c3f-6486-3g7g
Jun 25, 2026
Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52804
GO-2026-5110
GHSA-4565-r4x7-hg8j
Jun 25, 2026
Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52796
GO-2026-5124
GHSA-4j89-2c4f-44c6
Jun 25, 2026
Gogs has DoS in rendering issue index pattern in gogs.io/gogs Gogs has DoS in rendering issue index pattern in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-25921
GO-2026-4616
GHSA-cj4v-437j-jq4c
Mar 10, 2026
Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26195
GO-2026-4618
GHSA-vgvf-m4fw-938j
Mar 10, 2026
Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26276
GO-2026-4627
GHSA-vgjm-2cpf-4g7c
Mar 10, 2026
Gogs: DOM-based XSS via milestone selection in gogs.io/gogs Gogs: DOM-based XSS via milestone selection in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26022
GO-2026-4620
GHSA-xrcr-gmf5-2r8j
Mar 10, 2026
Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26194
GO-2026-4617
GHSA-v9vm-r24h-6rqm
Mar 10, 2026
Gogs: Release tag option injection in release deletion in gogs.io/gogs Gogs: Release tag option injection in release deletion in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26196
GO-2026-4619
GHSA-x9p5-w45c-7ffc
Mar 10, 2026
Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-25229
GO-2026-4499
GHSA-cv22-72px-f4gh
Feb 23, 2026
Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25232
GO-2026-4498
GHSA-2c6v-8r3v-gh6p
Feb 23, 2026
Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.1. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25120
GO-2026-4501
GHSA-jj5m-h57j-5gv7
Feb 23, 2026
Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25242
GO-2026-4500
GHSA-fc3h-92p8-h36f
Feb 23, 2026
Unauthenticated File Upload in Gogs in gogs.io/gogs Unauthenticated File Upload in Gogs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.1. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-23632
GO-2026-4450
GHSA-5qhx-gwfj-6jqr
Feb 17, 2026
Gogs user can update repository content with read-only permission in gogs.io/gogs Gogs user can update repository content with read-only permission in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4454
GHSA-26gq-grmh-6xm6
Feb 17, 2026
Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References
Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-64175
GO-2026-4449
GHSA-p6x6-9mx6-26wj
Feb 17, 2026
Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-23633
GO-2026-4453
GHSA-mrph-w4hh-gx3g
Feb 17, 2026
Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24135
GO-2026-4452
GHSA-jp7c-wj6q-3qf2
Feb 17, 2026
Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65852
GO-2026-4457
GHSA-rjv5-9px2-fqw6
Feb 17, 2026
Gogs has authorization bypass in repository deletion API in gogs.io/gogs Gogs has authorization bypass in repository deletion API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-64111
GO-2026-4448
GHSA-gg64-xxr9-qhjp
Feb 17, 2026
Gogs's update .git/config file allows remote command execution in gogs.io/gogs Gogs's update .git/config file allows remote command execution in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-22592
GO-2026-4451
GHSA-cr88-6mqm-4g57
Feb 17, 2026
Gogs has a Denial of Service issue in gogs.io/gogs Gogs has a Denial of Service issue in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References
Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-8110
GO-2025-4225
GHSA-mq8m-42gh-wq7r
Dec 15, 2025
Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-47943
GO-2025-3778
GHSA-xh32-cx6c-cp4v
Jul 28, 2025
Gogs XSS allowed by stored call in PDF renderer in gogs.io/gogs Gogs XSS allowed by stored call in PDF renderer in gogs.io/gogs Fixed in
0.13.3-0.20250608224432-110117b2e5e5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-56731
GO-2025-3776
GHSA-wj44-9vcg-wjq7
Jul 28, 2025
Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs Fixed in
0.13.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-55947
GO-2024-3356
GHSA-qf5v-rp47-55gg
Jan 07, 2025
Path Traversal in file update API in gogs in gogs.io/gogs Path Traversal in file update API in gogs in gogs.io/gogs Fixed in
0.13.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-54148
GO-2024-3355
GHSA-r7j8-5h9c-f6fx
Jan 07, 2025
Remote Command Execution in file editing in gogs in gogs.io/gogs Remote Command Execution in file editing in gogs in gogs.io/gogs Fixed in
0.13.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39930
GHSA-vm62-9jw3-c8w3
GHSA-p69r-v3h4-rj4f
GO-2024-2969
Dec 23, 2024
Gogs has an argument Injection in the built-in SSH server
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhen the built-in SSH server is enabled ( PatchesThe WorkaroundsDisable the use of built-in SSH server on operating systems other than Windows. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39930 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39932
GHSA-9pp6-wq8c-3w2c
GHSA-hf29-9hfh-w63j
GO-2024-2971
Dec 23, 2024
Gogs allows argument injection during the previewing of changes
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactUnprivileged user accounts can write to arbitrary files on the filesystem. We could demonstrate its exploitation to force a re-installation of the instance, granting administrator rights. It allows accessing and altering any user's code hosted on the same instance. PatchesUnintended Git options has been ignored for diff preview (https://github.com/gogs/gogs/pull/7871). Users should upgrade to 0.13.1 or the latest 0.14.0+dev. WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39932 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39931
GHSA-ccqv-43vm-4f3w
GHSA-2vgj-3pvg-xh4w
GO-2024-2970
Dec 23, 2024
Gogs allows deletion of internal files
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactUnprivileged user accounts can execute arbitrary commands on the Gogs instance with the privileges of the account specified by PatchesDeletion of WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39931 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39933
GHSA-m27m-h5gj-wwmg
GHSA-8mm6-wmpp-mmm3
GO-2024-2972
Dec 23, 2024
Gogs allows argument Injection when tagging new releases
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactUnprivileged user accounts with at least one SSH key can read arbitrary files on the system. For instance, they could leak the configuration files that could contain database credentials ( PatchesUnintended Git options has been ignored for creating tags (https://github.com/gogs/gogs/pull/7872). Users should upgrade to 0.13.1 or the latest 0.14.0+dev. WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39933 Fixed in
0.13.1
References
Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-44625
GO-2024-3275
GHSA-phm4-wf3h-pc3r
Nov 19, 2024
Unpatched Remote Code Execution in Gogs in gogs.io/gogs Unpatched Remote Code Execution in Gogs in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-32174
GO-2022-1060
GHSA-mcjj-2fvq-mc3r
Aug 21, 2024
Gogs vulnerable to Cross-site Scripting in gogs.io/gogs Gogs vulnerable to Cross-site Scripting in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2024
GO-2023-1596
GHSA-pfvh-p8qp-9ww9
Aug 20, 2024
Gogs OS Command Injection vulnerability in gogs.io/gogs Gogs OS Command Injection vulnerability in gogs.io/gogs Fixed in
0.12.11
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.12.10-rc.1
pre
Dependencies (49)
+ 41 more |
|
v0.12.9-rc.1
pre
58 CVEs
CVE-2026-52802
GO-2026-5773
GHSA-xxhq-69mf-w8cr
Jun 25, 2026
Gogs has an Open Redirect via redirect_to in gogs.io/gogs Gogs has an Open Redirect via redirect_to in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52814
GO-2026-5765
GHSA-xp79-5mx3-jx52
Jun 25, 2026
Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52801
GO-2026-5724
GHSA-wv27-2vqp-j7g5
Jun 25, 2026
Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-25119
GO-2026-5695
GHSA-w6j9-vw59-27wv
Jun 25, 2026
Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52810
GO-2026-5712
GHSA-wmfg-5p4h-5fw3
Jun 25, 2026
Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52807
GO-2026-5661
GHSA-vcm5-gvmp-78mp
Jun 25, 2026
Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52799
GO-2026-5536
GHSA-p9f5-h3rx-j5qw
Jun 25, 2026
Gogs Missing Authorization in Attachment Download in gogs.io/gogs Gogs Missing Authorization in Attachment Download in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52797
GO-2026-5545
GHSA-pm6v-2h4w-4rp2
Jun 25, 2026
Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52806
GO-2026-5580
GHSA-qf6p-p7ww-cwr9
Jun 25, 2026
Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52800
GO-2026-5556
GHSA-pwx3-qcgw-vh7h
Jun 25, 2026
Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52808
GO-2026-5065
GHSA-268j-37xf-pp52
Jun 25, 2026
Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52798
GO-2026-5477
GHSA-jq8v-rmf6-65jw
Jun 25, 2026
Gogs has Stored XSS in `.ipynb` Preview in gogs.io/gogs Gogs has Stored XSS in NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52805
GO-2026-5387
GHSA-g2f5-gjr4-qjvm
Jun 25, 2026
Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47267
GO-2026-5312
GHSA-c4v7-xg93-qf8g
Jun 25, 2026
Gogs has SSRF in webhook deliveries in gogs.io/gogs Gogs has SSRF in webhook deliveries in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52813
GO-2026-5305
GHSA-c39w-43gm-34h5
Jun 25, 2026
Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5193
GHSA-6vxv-wg6j-5qwp
Jun 25, 2026
Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52815
GO-2026-5202
GHSA-744x-3838-5r56
Jun 25, 2026
Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52812
GO-2026-5184
GHSA-6p9m-q3jp-47h4
Jun 25, 2026
Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52811
GO-2026-5249
GHSA-89mr-xqfv-758m
Jun 25, 2026
Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-64719
GO-2026-5098
GHSA-3qq3-668m-v9mj
Jun 25, 2026
Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52816
GO-2026-5103
GHSA-3w28-36p9-w929
Jun 25, 2026
Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52809
GO-2026-5140
GHSA-5c3f-6486-3g7g
Jun 25, 2026
Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52804
GO-2026-5110
GHSA-4565-r4x7-hg8j
Jun 25, 2026
Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52796
GO-2026-5124
GHSA-4j89-2c4f-44c6
Jun 25, 2026
Gogs has DoS in rendering issue index pattern in gogs.io/gogs Gogs has DoS in rendering issue index pattern in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-25921
GO-2026-4616
GHSA-cj4v-437j-jq4c
Mar 10, 2026
Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26195
GO-2026-4618
GHSA-vgvf-m4fw-938j
Mar 10, 2026
Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26276
GO-2026-4627
GHSA-vgjm-2cpf-4g7c
Mar 10, 2026
Gogs: DOM-based XSS via milestone selection in gogs.io/gogs Gogs: DOM-based XSS via milestone selection in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26022
GO-2026-4620
GHSA-xrcr-gmf5-2r8j
Mar 10, 2026
Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26194
GO-2026-4617
GHSA-v9vm-r24h-6rqm
Mar 10, 2026
Gogs: Release tag option injection in release deletion in gogs.io/gogs Gogs: Release tag option injection in release deletion in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26196
GO-2026-4619
GHSA-x9p5-w45c-7ffc
Mar 10, 2026
Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-25229
GO-2026-4499
GHSA-cv22-72px-f4gh
Feb 23, 2026
Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25232
GO-2026-4498
GHSA-2c6v-8r3v-gh6p
Feb 23, 2026
Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.1. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25120
GO-2026-4501
GHSA-jj5m-h57j-5gv7
Feb 23, 2026
Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25242
GO-2026-4500
GHSA-fc3h-92p8-h36f
Feb 23, 2026
Unauthenticated File Upload in Gogs in gogs.io/gogs Unauthenticated File Upload in Gogs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.1. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-23632
GO-2026-4450
GHSA-5qhx-gwfj-6jqr
Feb 17, 2026
Gogs user can update repository content with read-only permission in gogs.io/gogs Gogs user can update repository content with read-only permission in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4454
GHSA-26gq-grmh-6xm6
Feb 17, 2026
Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References
Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-64175
GO-2026-4449
GHSA-p6x6-9mx6-26wj
Feb 17, 2026
Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-23633
GO-2026-4453
GHSA-mrph-w4hh-gx3g
Feb 17, 2026
Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24135
GO-2026-4452
GHSA-jp7c-wj6q-3qf2
Feb 17, 2026
Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65852
GO-2026-4457
GHSA-rjv5-9px2-fqw6
Feb 17, 2026
Gogs has authorization bypass in repository deletion API in gogs.io/gogs Gogs has authorization bypass in repository deletion API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-64111
GO-2026-4448
GHSA-gg64-xxr9-qhjp
Feb 17, 2026
Gogs's update .git/config file allows remote command execution in gogs.io/gogs Gogs's update .git/config file allows remote command execution in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-22592
GO-2026-4451
GHSA-cr88-6mqm-4g57
Feb 17, 2026
Gogs has a Denial of Service issue in gogs.io/gogs Gogs has a Denial of Service issue in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References
Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-8110
GO-2025-4225
GHSA-mq8m-42gh-wq7r
Dec 15, 2025
Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-47943
GO-2025-3778
GHSA-xh32-cx6c-cp4v
Jul 28, 2025
Gogs XSS allowed by stored call in PDF renderer in gogs.io/gogs Gogs XSS allowed by stored call in PDF renderer in gogs.io/gogs Fixed in
0.13.3-0.20250608224432-110117b2e5e5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-56731
GO-2025-3776
GHSA-wj44-9vcg-wjq7
Jul 28, 2025
Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs Fixed in
0.13.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-55947
GO-2024-3356
GHSA-qf5v-rp47-55gg
Jan 07, 2025
Path Traversal in file update API in gogs in gogs.io/gogs Path Traversal in file update API in gogs in gogs.io/gogs Fixed in
0.13.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-54148
GO-2024-3355
GHSA-r7j8-5h9c-f6fx
Jan 07, 2025
Remote Command Execution in file editing in gogs in gogs.io/gogs Remote Command Execution in file editing in gogs in gogs.io/gogs Fixed in
0.13.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39930
GHSA-vm62-9jw3-c8w3
GHSA-p69r-v3h4-rj4f
GO-2024-2969
Dec 23, 2024
Gogs has an argument Injection in the built-in SSH server
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhen the built-in SSH server is enabled ( PatchesThe WorkaroundsDisable the use of built-in SSH server on operating systems other than Windows. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39930 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39932
GHSA-9pp6-wq8c-3w2c
GHSA-hf29-9hfh-w63j
GO-2024-2971
Dec 23, 2024
Gogs allows argument injection during the previewing of changes
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactUnprivileged user accounts can write to arbitrary files on the filesystem. We could demonstrate its exploitation to force a re-installation of the instance, granting administrator rights. It allows accessing and altering any user's code hosted on the same instance. PatchesUnintended Git options has been ignored for diff preview (https://github.com/gogs/gogs/pull/7871). Users should upgrade to 0.13.1 or the latest 0.14.0+dev. WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39932 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39931
GHSA-ccqv-43vm-4f3w
GHSA-2vgj-3pvg-xh4w
GO-2024-2970
Dec 23, 2024
Gogs allows deletion of internal files
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactUnprivileged user accounts can execute arbitrary commands on the Gogs instance with the privileges of the account specified by PatchesDeletion of WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39931 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39933
GHSA-m27m-h5gj-wwmg
GHSA-8mm6-wmpp-mmm3
GO-2024-2972
Dec 23, 2024
Gogs allows argument Injection when tagging new releases
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactUnprivileged user accounts with at least one SSH key can read arbitrary files on the system. For instance, they could leak the configuration files that could contain database credentials ( PatchesUnintended Git options has been ignored for creating tags (https://github.com/gogs/gogs/pull/7872). Users should upgrade to 0.13.1 or the latest 0.14.0+dev. WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39933 Fixed in
0.13.1
References
Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-44625
GO-2024-3275
GHSA-phm4-wf3h-pc3r
Nov 19, 2024
Unpatched Remote Code Execution in Gogs in gogs.io/gogs Unpatched Remote Code Execution in Gogs in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-32174
GO-2022-1060
GHSA-mcjj-2fvq-mc3r
Aug 21, 2024
Gogs vulnerable to Cross-site Scripting in gogs.io/gogs Gogs vulnerable to Cross-site Scripting in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1992
GO-2022-0570
GHSA-994f-7g86-qr56
Aug 21, 2024
Path Traversal in file editor on Windows in Gogs in gogs.io/gogs Path Traversal in file editor on Windows in Gogs in gogs.io/gogs Fixed in
0.12.9
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1986
GO-2022-0556
GHSA-67mx-jc2f-jgjm
Aug 21, 2024
OS Command Injection in file editor in Gogs in gogs.io/gogs OS Command Injection in file editor in Gogs in gogs.io/gogs Fixed in
0.12.9
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1993
GO-2022-0562
GHSA-6vcc-v9vw-g2x5
Aug 21, 2024
Path Traversal in Git HTTP endpoints in Gogs in gogs.io/gogs Path Traversal in Git HTTP endpoints in Gogs in gogs.io/gogs Fixed in
0.12.9
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31038
GO-2022-0483
GHSA-xq4v-vrp9-vcf2
Aug 21, 2024
Cross-site Scripting vulnerability in repository issue list in Gogs in gogs.io/gogs Cross-site Scripting vulnerability in repository issue list in Gogs in gogs.io/gogs Fixed in
0.12.9
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2024
GO-2023-1596
GHSA-pfvh-p8qp-9ww9
Aug 20, 2024
Gogs OS Command Injection vulnerability in gogs.io/gogs Gogs OS Command Injection vulnerability in gogs.io/gogs Fixed in
0.12.11
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.12.9-rc.1
pre
Dependencies (49)
+ 41 more |
|
v0.12.9
patch
54 CVEs
CVE-2026-52802
GO-2026-5773
GHSA-xxhq-69mf-w8cr
Jun 25, 2026
Gogs has an Open Redirect via redirect_to in gogs.io/gogs Gogs has an Open Redirect via redirect_to in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52814
GO-2026-5765
GHSA-xp79-5mx3-jx52
Jun 25, 2026
Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52801
GO-2026-5724
GHSA-wv27-2vqp-j7g5
Jun 25, 2026
Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-25119
GO-2026-5695
GHSA-w6j9-vw59-27wv
Jun 25, 2026
Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52810
GO-2026-5712
GHSA-wmfg-5p4h-5fw3
Jun 25, 2026
Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52807
GO-2026-5661
GHSA-vcm5-gvmp-78mp
Jun 25, 2026
Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52799
GO-2026-5536
GHSA-p9f5-h3rx-j5qw
Jun 25, 2026
Gogs Missing Authorization in Attachment Download in gogs.io/gogs Gogs Missing Authorization in Attachment Download in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52797
GO-2026-5545
GHSA-pm6v-2h4w-4rp2
Jun 25, 2026
Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52806
GO-2026-5580
GHSA-qf6p-p7ww-cwr9
Jun 25, 2026
Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52800
GO-2026-5556
GHSA-pwx3-qcgw-vh7h
Jun 25, 2026
Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52808
GO-2026-5065
GHSA-268j-37xf-pp52
Jun 25, 2026
Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52798
GO-2026-5477
GHSA-jq8v-rmf6-65jw
Jun 25, 2026
Gogs has Stored XSS in `.ipynb` Preview in gogs.io/gogs Gogs has Stored XSS in NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52805
GO-2026-5387
GHSA-g2f5-gjr4-qjvm
Jun 25, 2026
Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47267
GO-2026-5312
GHSA-c4v7-xg93-qf8g
Jun 25, 2026
Gogs has SSRF in webhook deliveries in gogs.io/gogs Gogs has SSRF in webhook deliveries in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52813
GO-2026-5305
GHSA-c39w-43gm-34h5
Jun 25, 2026
Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5193
GHSA-6vxv-wg6j-5qwp
Jun 25, 2026
Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52815
GO-2026-5202
GHSA-744x-3838-5r56
Jun 25, 2026
Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52812
GO-2026-5184
GHSA-6p9m-q3jp-47h4
Jun 25, 2026
Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52811
GO-2026-5249
GHSA-89mr-xqfv-758m
Jun 25, 2026
Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-64719
GO-2026-5098
GHSA-3qq3-668m-v9mj
Jun 25, 2026
Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52816
GO-2026-5103
GHSA-3w28-36p9-w929
Jun 25, 2026
Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52809
GO-2026-5140
GHSA-5c3f-6486-3g7g
Jun 25, 2026
Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52804
GO-2026-5110
GHSA-4565-r4x7-hg8j
Jun 25, 2026
Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52796
GO-2026-5124
GHSA-4j89-2c4f-44c6
Jun 25, 2026
Gogs has DoS in rendering issue index pattern in gogs.io/gogs Gogs has DoS in rendering issue index pattern in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-25921
GO-2026-4616
GHSA-cj4v-437j-jq4c
Mar 10, 2026
Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26195
GO-2026-4618
GHSA-vgvf-m4fw-938j
Mar 10, 2026
Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26276
GO-2026-4627
GHSA-vgjm-2cpf-4g7c
Mar 10, 2026
Gogs: DOM-based XSS via milestone selection in gogs.io/gogs Gogs: DOM-based XSS via milestone selection in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26022
GO-2026-4620
GHSA-xrcr-gmf5-2r8j
Mar 10, 2026
Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26194
GO-2026-4617
GHSA-v9vm-r24h-6rqm
Mar 10, 2026
Gogs: Release tag option injection in release deletion in gogs.io/gogs Gogs: Release tag option injection in release deletion in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26196
GO-2026-4619
GHSA-x9p5-w45c-7ffc
Mar 10, 2026
Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-25229
GO-2026-4499
GHSA-cv22-72px-f4gh
Feb 23, 2026
Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25232
GO-2026-4498
GHSA-2c6v-8r3v-gh6p
Feb 23, 2026
Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.1. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25120
GO-2026-4501
GHSA-jj5m-h57j-5gv7
Feb 23, 2026
Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25242
GO-2026-4500
GHSA-fc3h-92p8-h36f
Feb 23, 2026
Unauthenticated File Upload in Gogs in gogs.io/gogs Unauthenticated File Upload in Gogs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.1. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-23632
GO-2026-4450
GHSA-5qhx-gwfj-6jqr
Feb 17, 2026
Gogs user can update repository content with read-only permission in gogs.io/gogs Gogs user can update repository content with read-only permission in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4454
GHSA-26gq-grmh-6xm6
Feb 17, 2026
Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References
Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-64175
GO-2026-4449
GHSA-p6x6-9mx6-26wj
Feb 17, 2026
Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-23633
GO-2026-4453
GHSA-mrph-w4hh-gx3g
Feb 17, 2026
Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24135
GO-2026-4452
GHSA-jp7c-wj6q-3qf2
Feb 17, 2026
Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65852
GO-2026-4457
GHSA-rjv5-9px2-fqw6
Feb 17, 2026
Gogs has authorization bypass in repository deletion API in gogs.io/gogs Gogs has authorization bypass in repository deletion API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-64111
GO-2026-4448
GHSA-gg64-xxr9-qhjp
Feb 17, 2026
Gogs's update .git/config file allows remote command execution in gogs.io/gogs Gogs's update .git/config file allows remote command execution in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-22592
GO-2026-4451
GHSA-cr88-6mqm-4g57
Feb 17, 2026
Gogs has a Denial of Service issue in gogs.io/gogs Gogs has a Denial of Service issue in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References
Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-8110
GO-2025-4225
GHSA-mq8m-42gh-wq7r
Dec 15, 2025
Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-47943
GO-2025-3778
GHSA-xh32-cx6c-cp4v
Jul 28, 2025
Gogs XSS allowed by stored call in PDF renderer in gogs.io/gogs Gogs XSS allowed by stored call in PDF renderer in gogs.io/gogs Fixed in
0.13.3-0.20250608224432-110117b2e5e5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-56731
GO-2025-3776
GHSA-wj44-9vcg-wjq7
Jul 28, 2025
Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs Fixed in
0.13.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-55947
GO-2024-3356
GHSA-qf5v-rp47-55gg
Jan 07, 2025
Path Traversal in file update API in gogs in gogs.io/gogs Path Traversal in file update API in gogs in gogs.io/gogs Fixed in
0.13.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-54148
GO-2024-3355
GHSA-r7j8-5h9c-f6fx
Jan 07, 2025
Remote Command Execution in file editing in gogs in gogs.io/gogs Remote Command Execution in file editing in gogs in gogs.io/gogs Fixed in
0.13.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39930
GHSA-vm62-9jw3-c8w3
GHSA-p69r-v3h4-rj4f
GO-2024-2969
Dec 23, 2024
Gogs has an argument Injection in the built-in SSH server
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhen the built-in SSH server is enabled ( PatchesThe WorkaroundsDisable the use of built-in SSH server on operating systems other than Windows. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39930 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39932
GHSA-9pp6-wq8c-3w2c
GHSA-hf29-9hfh-w63j
GO-2024-2971
Dec 23, 2024
Gogs allows argument injection during the previewing of changes
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactUnprivileged user accounts can write to arbitrary files on the filesystem. We could demonstrate its exploitation to force a re-installation of the instance, granting administrator rights. It allows accessing and altering any user's code hosted on the same instance. PatchesUnintended Git options has been ignored for diff preview (https://github.com/gogs/gogs/pull/7871). Users should upgrade to 0.13.1 or the latest 0.14.0+dev. WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39932 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39931
GHSA-ccqv-43vm-4f3w
GHSA-2vgj-3pvg-xh4w
GO-2024-2970
Dec 23, 2024
Gogs allows deletion of internal files
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactUnprivileged user accounts can execute arbitrary commands on the Gogs instance with the privileges of the account specified by PatchesDeletion of WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39931 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39933
GHSA-m27m-h5gj-wwmg
GHSA-8mm6-wmpp-mmm3
GO-2024-2972
Dec 23, 2024
Gogs allows argument Injection when tagging new releases
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactUnprivileged user accounts with at least one SSH key can read arbitrary files on the system. For instance, they could leak the configuration files that could contain database credentials ( PatchesUnintended Git options has been ignored for creating tags (https://github.com/gogs/gogs/pull/7872). Users should upgrade to 0.13.1 or the latest 0.14.0+dev. WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39933 Fixed in
0.13.1
References
Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-44625
GO-2024-3275
GHSA-phm4-wf3h-pc3r
Nov 19, 2024
Unpatched Remote Code Execution in Gogs in gogs.io/gogs Unpatched Remote Code Execution in Gogs in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-32174
GO-2022-1060
GHSA-mcjj-2fvq-mc3r
Aug 21, 2024
Gogs vulnerable to Cross-site Scripting in gogs.io/gogs Gogs vulnerable to Cross-site Scripting in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2024
GO-2023-1596
GHSA-pfvh-p8qp-9ww9
Aug 20, 2024
Gogs OS Command Injection vulnerability in gogs.io/gogs Gogs OS Command Injection vulnerability in gogs.io/gogs Fixed in
0.12.11
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.12.9
patch
Dependencies (49)
+ 41 more |
|
v0.12.8
patch
58 CVEs
CVE-2026-52802
GO-2026-5773
GHSA-xxhq-69mf-w8cr
Jun 25, 2026
Gogs has an Open Redirect via redirect_to in gogs.io/gogs Gogs has an Open Redirect via redirect_to in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52814
GO-2026-5765
GHSA-xp79-5mx3-jx52
Jun 25, 2026
Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52801
GO-2026-5724
GHSA-wv27-2vqp-j7g5
Jun 25, 2026
Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-25119
GO-2026-5695
GHSA-w6j9-vw59-27wv
Jun 25, 2026
Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52810
GO-2026-5712
GHSA-wmfg-5p4h-5fw3
Jun 25, 2026
Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52807
GO-2026-5661
GHSA-vcm5-gvmp-78mp
Jun 25, 2026
Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52799
GO-2026-5536
GHSA-p9f5-h3rx-j5qw
Jun 25, 2026
Gogs Missing Authorization in Attachment Download in gogs.io/gogs Gogs Missing Authorization in Attachment Download in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52797
GO-2026-5545
GHSA-pm6v-2h4w-4rp2
Jun 25, 2026
Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52806
GO-2026-5580
GHSA-qf6p-p7ww-cwr9
Jun 25, 2026
Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52800
GO-2026-5556
GHSA-pwx3-qcgw-vh7h
Jun 25, 2026
Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52808
GO-2026-5065
GHSA-268j-37xf-pp52
Jun 25, 2026
Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52798
GO-2026-5477
GHSA-jq8v-rmf6-65jw
Jun 25, 2026
Gogs has Stored XSS in `.ipynb` Preview in gogs.io/gogs Gogs has Stored XSS in NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52805
GO-2026-5387
GHSA-g2f5-gjr4-qjvm
Jun 25, 2026
Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47267
GO-2026-5312
GHSA-c4v7-xg93-qf8g
Jun 25, 2026
Gogs has SSRF in webhook deliveries in gogs.io/gogs Gogs has SSRF in webhook deliveries in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52813
GO-2026-5305
GHSA-c39w-43gm-34h5
Jun 25, 2026
Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5193
GHSA-6vxv-wg6j-5qwp
Jun 25, 2026
Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52815
GO-2026-5202
GHSA-744x-3838-5r56
Jun 25, 2026
Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52812
GO-2026-5184
GHSA-6p9m-q3jp-47h4
Jun 25, 2026
Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52811
GO-2026-5249
GHSA-89mr-xqfv-758m
Jun 25, 2026
Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-64719
GO-2026-5098
GHSA-3qq3-668m-v9mj
Jun 25, 2026
Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52816
GO-2026-5103
GHSA-3w28-36p9-w929
Jun 25, 2026
Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52809
GO-2026-5140
GHSA-5c3f-6486-3g7g
Jun 25, 2026
Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52804
GO-2026-5110
GHSA-4565-r4x7-hg8j
Jun 25, 2026
Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52796
GO-2026-5124
GHSA-4j89-2c4f-44c6
Jun 25, 2026
Gogs has DoS in rendering issue index pattern in gogs.io/gogs Gogs has DoS in rendering issue index pattern in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-25921
GO-2026-4616
GHSA-cj4v-437j-jq4c
Mar 10, 2026
Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26195
GO-2026-4618
GHSA-vgvf-m4fw-938j
Mar 10, 2026
Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26276
GO-2026-4627
GHSA-vgjm-2cpf-4g7c
Mar 10, 2026
Gogs: DOM-based XSS via milestone selection in gogs.io/gogs Gogs: DOM-based XSS via milestone selection in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26022
GO-2026-4620
GHSA-xrcr-gmf5-2r8j
Mar 10, 2026
Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26194
GO-2026-4617
GHSA-v9vm-r24h-6rqm
Mar 10, 2026
Gogs: Release tag option injection in release deletion in gogs.io/gogs Gogs: Release tag option injection in release deletion in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26196
GO-2026-4619
GHSA-x9p5-w45c-7ffc
Mar 10, 2026
Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-25229
GO-2026-4499
GHSA-cv22-72px-f4gh
Feb 23, 2026
Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25232
GO-2026-4498
GHSA-2c6v-8r3v-gh6p
Feb 23, 2026
Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.1. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25120
GO-2026-4501
GHSA-jj5m-h57j-5gv7
Feb 23, 2026
Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25242
GO-2026-4500
GHSA-fc3h-92p8-h36f
Feb 23, 2026
Unauthenticated File Upload in Gogs in gogs.io/gogs Unauthenticated File Upload in Gogs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.1. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-23632
GO-2026-4450
GHSA-5qhx-gwfj-6jqr
Feb 17, 2026
Gogs user can update repository content with read-only permission in gogs.io/gogs Gogs user can update repository content with read-only permission in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4454
GHSA-26gq-grmh-6xm6
Feb 17, 2026
Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References
Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-64175
GO-2026-4449
GHSA-p6x6-9mx6-26wj
Feb 17, 2026
Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-23633
GO-2026-4453
GHSA-mrph-w4hh-gx3g
Feb 17, 2026
Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24135
GO-2026-4452
GHSA-jp7c-wj6q-3qf2
Feb 17, 2026
Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65852
GO-2026-4457
GHSA-rjv5-9px2-fqw6
Feb 17, 2026
Gogs has authorization bypass in repository deletion API in gogs.io/gogs Gogs has authorization bypass in repository deletion API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-64111
GO-2026-4448
GHSA-gg64-xxr9-qhjp
Feb 17, 2026
Gogs's update .git/config file allows remote command execution in gogs.io/gogs Gogs's update .git/config file allows remote command execution in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-22592
GO-2026-4451
GHSA-cr88-6mqm-4g57
Feb 17, 2026
Gogs has a Denial of Service issue in gogs.io/gogs Gogs has a Denial of Service issue in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References
Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-8110
GO-2025-4225
GHSA-mq8m-42gh-wq7r
Dec 15, 2025
Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-47943
GO-2025-3778
GHSA-xh32-cx6c-cp4v
Jul 28, 2025
Gogs XSS allowed by stored call in PDF renderer in gogs.io/gogs Gogs XSS allowed by stored call in PDF renderer in gogs.io/gogs Fixed in
0.13.3-0.20250608224432-110117b2e5e5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-56731
GO-2025-3776
GHSA-wj44-9vcg-wjq7
Jul 28, 2025
Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs Fixed in
0.13.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-55947
GO-2024-3356
GHSA-qf5v-rp47-55gg
Jan 07, 2025
Path Traversal in file update API in gogs in gogs.io/gogs Path Traversal in file update API in gogs in gogs.io/gogs Fixed in
0.13.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-54148
GO-2024-3355
GHSA-r7j8-5h9c-f6fx
Jan 07, 2025
Remote Command Execution in file editing in gogs in gogs.io/gogs Remote Command Execution in file editing in gogs in gogs.io/gogs Fixed in
0.13.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39930
GHSA-vm62-9jw3-c8w3
GHSA-p69r-v3h4-rj4f
GO-2024-2969
Dec 23, 2024
Gogs has an argument Injection in the built-in SSH server
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhen the built-in SSH server is enabled ( PatchesThe WorkaroundsDisable the use of built-in SSH server on operating systems other than Windows. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39930 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39932
GHSA-9pp6-wq8c-3w2c
GHSA-hf29-9hfh-w63j
GO-2024-2971
Dec 23, 2024
Gogs allows argument injection during the previewing of changes
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactUnprivileged user accounts can write to arbitrary files on the filesystem. We could demonstrate its exploitation to force a re-installation of the instance, granting administrator rights. It allows accessing and altering any user's code hosted on the same instance. PatchesUnintended Git options has been ignored for diff preview (https://github.com/gogs/gogs/pull/7871). Users should upgrade to 0.13.1 or the latest 0.14.0+dev. WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39932 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39931
GHSA-ccqv-43vm-4f3w
GHSA-2vgj-3pvg-xh4w
GO-2024-2970
Dec 23, 2024
Gogs allows deletion of internal files
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactUnprivileged user accounts can execute arbitrary commands on the Gogs instance with the privileges of the account specified by PatchesDeletion of WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39931 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39933
GHSA-m27m-h5gj-wwmg
GHSA-8mm6-wmpp-mmm3
GO-2024-2972
Dec 23, 2024
Gogs allows argument Injection when tagging new releases
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactUnprivileged user accounts with at least one SSH key can read arbitrary files on the system. For instance, they could leak the configuration files that could contain database credentials ( PatchesUnintended Git options has been ignored for creating tags (https://github.com/gogs/gogs/pull/7872). Users should upgrade to 0.13.1 or the latest 0.14.0+dev. WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39933 Fixed in
0.13.1
References
Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-44625
GO-2024-3275
GHSA-phm4-wf3h-pc3r
Nov 19, 2024
Unpatched Remote Code Execution in Gogs in gogs.io/gogs Unpatched Remote Code Execution in Gogs in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-32174
GO-2022-1060
GHSA-mcjj-2fvq-mc3r
Aug 21, 2024
Gogs vulnerable to Cross-site Scripting in gogs.io/gogs Gogs vulnerable to Cross-site Scripting in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1992
GO-2022-0570
GHSA-994f-7g86-qr56
Aug 21, 2024
Path Traversal in file editor on Windows in Gogs in gogs.io/gogs Path Traversal in file editor on Windows in Gogs in gogs.io/gogs Fixed in
0.12.9
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1986
GO-2022-0556
GHSA-67mx-jc2f-jgjm
Aug 21, 2024
OS Command Injection in file editor in Gogs in gogs.io/gogs OS Command Injection in file editor in Gogs in gogs.io/gogs Fixed in
0.12.9
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1993
GO-2022-0562
GHSA-6vcc-v9vw-g2x5
Aug 21, 2024
Path Traversal in Git HTTP endpoints in Gogs in gogs.io/gogs Path Traversal in Git HTTP endpoints in Gogs in gogs.io/gogs Fixed in
0.12.9
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31038
GO-2022-0483
GHSA-xq4v-vrp9-vcf2
Aug 21, 2024
Cross-site Scripting vulnerability in repository issue list in Gogs in gogs.io/gogs Cross-site Scripting vulnerability in repository issue list in Gogs in gogs.io/gogs Fixed in
0.12.9
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2024
GO-2023-1596
GHSA-pfvh-p8qp-9ww9
Aug 20, 2024
Gogs OS Command Injection vulnerability in gogs.io/gogs Gogs OS Command Injection vulnerability in gogs.io/gogs Fixed in
0.12.11
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.12.8
patch
Dependencies (49)
+ 41 more |
|
v0.12.8-rc.1
pre
62 CVEs
CVE-2026-52802
GO-2026-5773
GHSA-xxhq-69mf-w8cr
Jun 25, 2026
Gogs has an Open Redirect via redirect_to in gogs.io/gogs Gogs has an Open Redirect via redirect_to in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52814
GO-2026-5765
GHSA-xp79-5mx3-jx52
Jun 25, 2026
Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52801
GO-2026-5724
GHSA-wv27-2vqp-j7g5
Jun 25, 2026
Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-25119
GO-2026-5695
GHSA-w6j9-vw59-27wv
Jun 25, 2026
Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52810
GO-2026-5712
GHSA-wmfg-5p4h-5fw3
Jun 25, 2026
Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52807
GO-2026-5661
GHSA-vcm5-gvmp-78mp
Jun 25, 2026
Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52799
GO-2026-5536
GHSA-p9f5-h3rx-j5qw
Jun 25, 2026
Gogs Missing Authorization in Attachment Download in gogs.io/gogs Gogs Missing Authorization in Attachment Download in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52797
GO-2026-5545
GHSA-pm6v-2h4w-4rp2
Jun 25, 2026
Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52806
GO-2026-5580
GHSA-qf6p-p7ww-cwr9
Jun 25, 2026
Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52800
GO-2026-5556
GHSA-pwx3-qcgw-vh7h
Jun 25, 2026
Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52808
GO-2026-5065
GHSA-268j-37xf-pp52
Jun 25, 2026
Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52798
GO-2026-5477
GHSA-jq8v-rmf6-65jw
Jun 25, 2026
Gogs has Stored XSS in `.ipynb` Preview in gogs.io/gogs Gogs has Stored XSS in NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52805
GO-2026-5387
GHSA-g2f5-gjr4-qjvm
Jun 25, 2026
Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47267
GO-2026-5312
GHSA-c4v7-xg93-qf8g
Jun 25, 2026
Gogs has SSRF in webhook deliveries in gogs.io/gogs Gogs has SSRF in webhook deliveries in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52813
GO-2026-5305
GHSA-c39w-43gm-34h5
Jun 25, 2026
Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5193
GHSA-6vxv-wg6j-5qwp
Jun 25, 2026
Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52815
GO-2026-5202
GHSA-744x-3838-5r56
Jun 25, 2026
Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52812
GO-2026-5184
GHSA-6p9m-q3jp-47h4
Jun 25, 2026
Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52811
GO-2026-5249
GHSA-89mr-xqfv-758m
Jun 25, 2026
Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-64719
GO-2026-5098
GHSA-3qq3-668m-v9mj
Jun 25, 2026
Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52816
GO-2026-5103
GHSA-3w28-36p9-w929
Jun 25, 2026
Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52809
GO-2026-5140
GHSA-5c3f-6486-3g7g
Jun 25, 2026
Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52804
GO-2026-5110
GHSA-4565-r4x7-hg8j
Jun 25, 2026
Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52796
GO-2026-5124
GHSA-4j89-2c4f-44c6
Jun 25, 2026
Gogs has DoS in rendering issue index pattern in gogs.io/gogs Gogs has DoS in rendering issue index pattern in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-25921
GO-2026-4616
GHSA-cj4v-437j-jq4c
Mar 10, 2026
Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26195
GO-2026-4618
GHSA-vgvf-m4fw-938j
Mar 10, 2026
Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26276
GO-2026-4627
GHSA-vgjm-2cpf-4g7c
Mar 10, 2026
Gogs: DOM-based XSS via milestone selection in gogs.io/gogs Gogs: DOM-based XSS via milestone selection in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26022
GO-2026-4620
GHSA-xrcr-gmf5-2r8j
Mar 10, 2026
Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26194
GO-2026-4617
GHSA-v9vm-r24h-6rqm
Mar 10, 2026
Gogs: Release tag option injection in release deletion in gogs.io/gogs Gogs: Release tag option injection in release deletion in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26196
GO-2026-4619
GHSA-x9p5-w45c-7ffc
Mar 10, 2026
Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-25229
GO-2026-4499
GHSA-cv22-72px-f4gh
Feb 23, 2026
Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25232
GO-2026-4498
GHSA-2c6v-8r3v-gh6p
Feb 23, 2026
Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.1. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25120
GO-2026-4501
GHSA-jj5m-h57j-5gv7
Feb 23, 2026
Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25242
GO-2026-4500
GHSA-fc3h-92p8-h36f
Feb 23, 2026
Unauthenticated File Upload in Gogs in gogs.io/gogs Unauthenticated File Upload in Gogs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.1. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-23632
GO-2026-4450
GHSA-5qhx-gwfj-6jqr
Feb 17, 2026
Gogs user can update repository content with read-only permission in gogs.io/gogs Gogs user can update repository content with read-only permission in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4454
GHSA-26gq-grmh-6xm6
Feb 17, 2026
Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References
Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-64175
GO-2026-4449
GHSA-p6x6-9mx6-26wj
Feb 17, 2026
Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-23633
GO-2026-4453
GHSA-mrph-w4hh-gx3g
Feb 17, 2026
Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24135
GO-2026-4452
GHSA-jp7c-wj6q-3qf2
Feb 17, 2026
Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65852
GO-2026-4457
GHSA-rjv5-9px2-fqw6
Feb 17, 2026
Gogs has authorization bypass in repository deletion API in gogs.io/gogs Gogs has authorization bypass in repository deletion API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-64111
GO-2026-4448
GHSA-gg64-xxr9-qhjp
Feb 17, 2026
Gogs's update .git/config file allows remote command execution in gogs.io/gogs Gogs's update .git/config file allows remote command execution in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-22592
GO-2026-4451
GHSA-cr88-6mqm-4g57
Feb 17, 2026
Gogs has a Denial of Service issue in gogs.io/gogs Gogs has a Denial of Service issue in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References
Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-8110
GO-2025-4225
GHSA-mq8m-42gh-wq7r
Dec 15, 2025
Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-47943
GO-2025-3778
GHSA-xh32-cx6c-cp4v
Jul 28, 2025
Gogs XSS allowed by stored call in PDF renderer in gogs.io/gogs Gogs XSS allowed by stored call in PDF renderer in gogs.io/gogs Fixed in
0.13.3-0.20250608224432-110117b2e5e5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-56731
GO-2025-3776
GHSA-wj44-9vcg-wjq7
Jul 28, 2025
Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs Fixed in
0.13.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-55947
GO-2024-3356
GHSA-qf5v-rp47-55gg
Jan 07, 2025
Path Traversal in file update API in gogs in gogs.io/gogs Path Traversal in file update API in gogs in gogs.io/gogs Fixed in
0.13.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-54148
GO-2024-3355
GHSA-r7j8-5h9c-f6fx
Jan 07, 2025
Remote Command Execution in file editing in gogs in gogs.io/gogs Remote Command Execution in file editing in gogs in gogs.io/gogs Fixed in
0.13.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39930
GHSA-vm62-9jw3-c8w3
GHSA-p69r-v3h4-rj4f
GO-2024-2969
Dec 23, 2024
Gogs has an argument Injection in the built-in SSH server
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhen the built-in SSH server is enabled ( PatchesThe WorkaroundsDisable the use of built-in SSH server on operating systems other than Windows. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39930 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39932
GHSA-9pp6-wq8c-3w2c
GHSA-hf29-9hfh-w63j
GO-2024-2971
Dec 23, 2024
Gogs allows argument injection during the previewing of changes
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactUnprivileged user accounts can write to arbitrary files on the filesystem. We could demonstrate its exploitation to force a re-installation of the instance, granting administrator rights. It allows accessing and altering any user's code hosted on the same instance. PatchesUnintended Git options has been ignored for diff preview (https://github.com/gogs/gogs/pull/7871). Users should upgrade to 0.13.1 or the latest 0.14.0+dev. WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39932 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39931
GHSA-ccqv-43vm-4f3w
GHSA-2vgj-3pvg-xh4w
GO-2024-2970
Dec 23, 2024
Gogs allows deletion of internal files
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactUnprivileged user accounts can execute arbitrary commands on the Gogs instance with the privileges of the account specified by PatchesDeletion of WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39931 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39933
GHSA-m27m-h5gj-wwmg
GHSA-8mm6-wmpp-mmm3
GO-2024-2972
Dec 23, 2024
Gogs allows argument Injection when tagging new releases
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactUnprivileged user accounts with at least one SSH key can read arbitrary files on the system. For instance, they could leak the configuration files that could contain database credentials ( PatchesUnintended Git options has been ignored for creating tags (https://github.com/gogs/gogs/pull/7872). Users should upgrade to 0.13.1 or the latest 0.14.0+dev. WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39933 Fixed in
0.13.1
References
Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-44625
GO-2024-3275
GHSA-phm4-wf3h-pc3r
Nov 19, 2024
Unpatched Remote Code Execution in Gogs in gogs.io/gogs Unpatched Remote Code Execution in Gogs in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-32174
GO-2022-1060
GHSA-mcjj-2fvq-mc3r
Aug 21, 2024
Gogs vulnerable to Cross-site Scripting in gogs.io/gogs Gogs vulnerable to Cross-site Scripting in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1884
GO-2022-0749
GHSA-958j-443g-7mm7
Aug 21, 2024
OS Command Injection in gogs in gogs.io/gogs OS Command Injection in gogs in gogs.io/gogs Fixed in
0.12.8
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1285
GO-2022-0583
GHSA-w689-557m-2cvq
Aug 21, 2024
Server-Side Request Forgery in gogs webhook in gogs.io/gogs Server-Side Request Forgery in gogs webhook in gogs.io/gogs Fixed in
0.12.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1992
GO-2022-0570
GHSA-994f-7g86-qr56
Aug 21, 2024
Path Traversal in file editor on Windows in Gogs in gogs.io/gogs Path Traversal in file editor on Windows in Gogs in gogs.io/gogs Fixed in
0.12.9
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1986
GO-2022-0556
GHSA-67mx-jc2f-jgjm
Aug 21, 2024
OS Command Injection in file editor in Gogs in gogs.io/gogs OS Command Injection in file editor in Gogs in gogs.io/gogs Fixed in
0.12.9
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1993
GO-2022-0562
GHSA-6vcc-v9vw-g2x5
Aug 21, 2024
Path Traversal in Git HTTP endpoints in Gogs in gogs.io/gogs Path Traversal in Git HTTP endpoints in Gogs in gogs.io/gogs Fixed in
0.12.9
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0473
GHSA-pj96-4jhv-v792
Aug 21, 2024
Cross site scripting via cookies in gogs in gogs.io/gogs Cross site scripting via cookies in gogs in gogs.io/gogs Fixed in
0.12.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31038
GO-2022-0483
GHSA-xq4v-vrp9-vcf2
Aug 21, 2024
Cross-site Scripting vulnerability in repository issue list in Gogs in gogs.io/gogs Cross-site Scripting vulnerability in repository issue list in Gogs in gogs.io/gogs Fixed in
0.12.9
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-32546
GO-2022-0471
GHSA-56j7-2pm8-rgmx
Aug 21, 2024
OS Command Injection in gogs in gogs.io/gogs OS Command Injection in gogs in gogs.io/gogs Fixed in
0.12.8
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2024
GO-2023-1596
GHSA-pfvh-p8qp-9ww9
Aug 20, 2024
Gogs OS Command Injection vulnerability in gogs.io/gogs Gogs OS Command Injection vulnerability in gogs.io/gogs Fixed in
0.12.11
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.12.8-rc.1
pre
Dependencies (49)
+ 41 more |
|
v0.12.7
patch
62 CVEs
CVE-2026-52802
GO-2026-5773
GHSA-xxhq-69mf-w8cr
Jun 25, 2026
Gogs has an Open Redirect via redirect_to in gogs.io/gogs Gogs has an Open Redirect via redirect_to in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52814
GO-2026-5765
GHSA-xp79-5mx3-jx52
Jun 25, 2026
Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52801
GO-2026-5724
GHSA-wv27-2vqp-j7g5
Jun 25, 2026
Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-25119
GO-2026-5695
GHSA-w6j9-vw59-27wv
Jun 25, 2026
Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52810
GO-2026-5712
GHSA-wmfg-5p4h-5fw3
Jun 25, 2026
Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52807
GO-2026-5661
GHSA-vcm5-gvmp-78mp
Jun 25, 2026
Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52799
GO-2026-5536
GHSA-p9f5-h3rx-j5qw
Jun 25, 2026
Gogs Missing Authorization in Attachment Download in gogs.io/gogs Gogs Missing Authorization in Attachment Download in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52797
GO-2026-5545
GHSA-pm6v-2h4w-4rp2
Jun 25, 2026
Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52806
GO-2026-5580
GHSA-qf6p-p7ww-cwr9
Jun 25, 2026
Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52800
GO-2026-5556
GHSA-pwx3-qcgw-vh7h
Jun 25, 2026
Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52808
GO-2026-5065
GHSA-268j-37xf-pp52
Jun 25, 2026
Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52798
GO-2026-5477
GHSA-jq8v-rmf6-65jw
Jun 25, 2026
Gogs has Stored XSS in `.ipynb` Preview in gogs.io/gogs Gogs has Stored XSS in NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52805
GO-2026-5387
GHSA-g2f5-gjr4-qjvm
Jun 25, 2026
Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47267
GO-2026-5312
GHSA-c4v7-xg93-qf8g
Jun 25, 2026
Gogs has SSRF in webhook deliveries in gogs.io/gogs Gogs has SSRF in webhook deliveries in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52813
GO-2026-5305
GHSA-c39w-43gm-34h5
Jun 25, 2026
Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5193
GHSA-6vxv-wg6j-5qwp
Jun 25, 2026
Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52815
GO-2026-5202
GHSA-744x-3838-5r56
Jun 25, 2026
Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52812
GO-2026-5184
GHSA-6p9m-q3jp-47h4
Jun 25, 2026
Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52811
GO-2026-5249
GHSA-89mr-xqfv-758m
Jun 25, 2026
Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-64719
GO-2026-5098
GHSA-3qq3-668m-v9mj
Jun 25, 2026
Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52816
GO-2026-5103
GHSA-3w28-36p9-w929
Jun 25, 2026
Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52809
GO-2026-5140
GHSA-5c3f-6486-3g7g
Jun 25, 2026
Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52804
GO-2026-5110
GHSA-4565-r4x7-hg8j
Jun 25, 2026
Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52796
GO-2026-5124
GHSA-4j89-2c4f-44c6
Jun 25, 2026
Gogs has DoS in rendering issue index pattern in gogs.io/gogs Gogs has DoS in rendering issue index pattern in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-25921
GO-2026-4616
GHSA-cj4v-437j-jq4c
Mar 10, 2026
Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26195
GO-2026-4618
GHSA-vgvf-m4fw-938j
Mar 10, 2026
Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26276
GO-2026-4627
GHSA-vgjm-2cpf-4g7c
Mar 10, 2026
Gogs: DOM-based XSS via milestone selection in gogs.io/gogs Gogs: DOM-based XSS via milestone selection in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26022
GO-2026-4620
GHSA-xrcr-gmf5-2r8j
Mar 10, 2026
Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26194
GO-2026-4617
GHSA-v9vm-r24h-6rqm
Mar 10, 2026
Gogs: Release tag option injection in release deletion in gogs.io/gogs Gogs: Release tag option injection in release deletion in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26196
GO-2026-4619
GHSA-x9p5-w45c-7ffc
Mar 10, 2026
Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-25229
GO-2026-4499
GHSA-cv22-72px-f4gh
Feb 23, 2026
Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25232
GO-2026-4498
GHSA-2c6v-8r3v-gh6p
Feb 23, 2026
Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.1. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25120
GO-2026-4501
GHSA-jj5m-h57j-5gv7
Feb 23, 2026
Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25242
GO-2026-4500
GHSA-fc3h-92p8-h36f
Feb 23, 2026
Unauthenticated File Upload in Gogs in gogs.io/gogs Unauthenticated File Upload in Gogs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.1. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-23632
GO-2026-4450
GHSA-5qhx-gwfj-6jqr
Feb 17, 2026
Gogs user can update repository content with read-only permission in gogs.io/gogs Gogs user can update repository content with read-only permission in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4454
GHSA-26gq-grmh-6xm6
Feb 17, 2026
Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References
Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-64175
GO-2026-4449
GHSA-p6x6-9mx6-26wj
Feb 17, 2026
Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-23633
GO-2026-4453
GHSA-mrph-w4hh-gx3g
Feb 17, 2026
Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24135
GO-2026-4452
GHSA-jp7c-wj6q-3qf2
Feb 17, 2026
Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65852
GO-2026-4457
GHSA-rjv5-9px2-fqw6
Feb 17, 2026
Gogs has authorization bypass in repository deletion API in gogs.io/gogs Gogs has authorization bypass in repository deletion API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-64111
GO-2026-4448
GHSA-gg64-xxr9-qhjp
Feb 17, 2026
Gogs's update .git/config file allows remote command execution in gogs.io/gogs Gogs's update .git/config file allows remote command execution in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-22592
GO-2026-4451
GHSA-cr88-6mqm-4g57
Feb 17, 2026
Gogs has a Denial of Service issue in gogs.io/gogs Gogs has a Denial of Service issue in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References
Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-8110
GO-2025-4225
GHSA-mq8m-42gh-wq7r
Dec 15, 2025
Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-47943
GO-2025-3778
GHSA-xh32-cx6c-cp4v
Jul 28, 2025
Gogs XSS allowed by stored call in PDF renderer in gogs.io/gogs Gogs XSS allowed by stored call in PDF renderer in gogs.io/gogs Fixed in
0.13.3-0.20250608224432-110117b2e5e5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-56731
GO-2025-3776
GHSA-wj44-9vcg-wjq7
Jul 28, 2025
Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs Fixed in
0.13.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-55947
GO-2024-3356
GHSA-qf5v-rp47-55gg
Jan 07, 2025
Path Traversal in file update API in gogs in gogs.io/gogs Path Traversal in file update API in gogs in gogs.io/gogs Fixed in
0.13.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-54148
GO-2024-3355
GHSA-r7j8-5h9c-f6fx
Jan 07, 2025
Remote Command Execution in file editing in gogs in gogs.io/gogs Remote Command Execution in file editing in gogs in gogs.io/gogs Fixed in
0.13.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39930
GHSA-vm62-9jw3-c8w3
GHSA-p69r-v3h4-rj4f
GO-2024-2969
Dec 23, 2024
Gogs has an argument Injection in the built-in SSH server
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhen the built-in SSH server is enabled ( PatchesThe WorkaroundsDisable the use of built-in SSH server on operating systems other than Windows. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39930 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39932
GHSA-9pp6-wq8c-3w2c
GHSA-hf29-9hfh-w63j
GO-2024-2971
Dec 23, 2024
Gogs allows argument injection during the previewing of changes
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactUnprivileged user accounts can write to arbitrary files on the filesystem. We could demonstrate its exploitation to force a re-installation of the instance, granting administrator rights. It allows accessing and altering any user's code hosted on the same instance. PatchesUnintended Git options has been ignored for diff preview (https://github.com/gogs/gogs/pull/7871). Users should upgrade to 0.13.1 or the latest 0.14.0+dev. WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39932 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39931
GHSA-ccqv-43vm-4f3w
GHSA-2vgj-3pvg-xh4w
GO-2024-2970
Dec 23, 2024
Gogs allows deletion of internal files
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactUnprivileged user accounts can execute arbitrary commands on the Gogs instance with the privileges of the account specified by PatchesDeletion of WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39931 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39933
GHSA-m27m-h5gj-wwmg
GHSA-8mm6-wmpp-mmm3
GO-2024-2972
Dec 23, 2024
Gogs allows argument Injection when tagging new releases
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactUnprivileged user accounts with at least one SSH key can read arbitrary files on the system. For instance, they could leak the configuration files that could contain database credentials ( PatchesUnintended Git options has been ignored for creating tags (https://github.com/gogs/gogs/pull/7872). Users should upgrade to 0.13.1 or the latest 0.14.0+dev. WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39933 Fixed in
0.13.1
References
Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-44625
GO-2024-3275
GHSA-phm4-wf3h-pc3r
Nov 19, 2024
Unpatched Remote Code Execution in Gogs in gogs.io/gogs Unpatched Remote Code Execution in Gogs in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-32174
GO-2022-1060
GHSA-mcjj-2fvq-mc3r
Aug 21, 2024
Gogs vulnerable to Cross-site Scripting in gogs.io/gogs Gogs vulnerable to Cross-site Scripting in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1884
GO-2022-0749
GHSA-958j-443g-7mm7
Aug 21, 2024
OS Command Injection in gogs in gogs.io/gogs OS Command Injection in gogs in gogs.io/gogs Fixed in
0.12.8
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1285
GO-2022-0583
GHSA-w689-557m-2cvq
Aug 21, 2024
Server-Side Request Forgery in gogs webhook in gogs.io/gogs Server-Side Request Forgery in gogs webhook in gogs.io/gogs Fixed in
0.12.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1992
GO-2022-0570
GHSA-994f-7g86-qr56
Aug 21, 2024
Path Traversal in file editor on Windows in Gogs in gogs.io/gogs Path Traversal in file editor on Windows in Gogs in gogs.io/gogs Fixed in
0.12.9
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1986
GO-2022-0556
GHSA-67mx-jc2f-jgjm
Aug 21, 2024
OS Command Injection in file editor in Gogs in gogs.io/gogs OS Command Injection in file editor in Gogs in gogs.io/gogs Fixed in
0.12.9
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1993
GO-2022-0562
GHSA-6vcc-v9vw-g2x5
Aug 21, 2024
Path Traversal in Git HTTP endpoints in Gogs in gogs.io/gogs Path Traversal in Git HTTP endpoints in Gogs in gogs.io/gogs Fixed in
0.12.9
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0473
GHSA-pj96-4jhv-v792
Aug 21, 2024
Cross site scripting via cookies in gogs in gogs.io/gogs Cross site scripting via cookies in gogs in gogs.io/gogs Fixed in
0.12.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31038
GO-2022-0483
GHSA-xq4v-vrp9-vcf2
Aug 21, 2024
Cross-site Scripting vulnerability in repository issue list in Gogs in gogs.io/gogs Cross-site Scripting vulnerability in repository issue list in Gogs in gogs.io/gogs Fixed in
0.12.9
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-32546
GO-2022-0471
GHSA-56j7-2pm8-rgmx
Aug 21, 2024
OS Command Injection in gogs in gogs.io/gogs OS Command Injection in gogs in gogs.io/gogs Fixed in
0.12.8
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2024
GO-2023-1596
GHSA-pfvh-p8qp-9ww9
Aug 20, 2024
Gogs OS Command Injection vulnerability in gogs.io/gogs Gogs OS Command Injection vulnerability in gogs.io/gogs Fixed in
0.12.11
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.12.7
patch
Dependencies (49)
+ 41 more |
|
v0.12.7-rc.1
pre
63 CVEs
CVE-2026-52802
GO-2026-5773
GHSA-xxhq-69mf-w8cr
Jun 25, 2026
Gogs has an Open Redirect via redirect_to in gogs.io/gogs Gogs has an Open Redirect via redirect_to in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52814
GO-2026-5765
GHSA-xp79-5mx3-jx52
Jun 25, 2026
Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52801
GO-2026-5724
GHSA-wv27-2vqp-j7g5
Jun 25, 2026
Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-25119
GO-2026-5695
GHSA-w6j9-vw59-27wv
Jun 25, 2026
Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52810
GO-2026-5712
GHSA-wmfg-5p4h-5fw3
Jun 25, 2026
Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52807
GO-2026-5661
GHSA-vcm5-gvmp-78mp
Jun 25, 2026
Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52799
GO-2026-5536
GHSA-p9f5-h3rx-j5qw
Jun 25, 2026
Gogs Missing Authorization in Attachment Download in gogs.io/gogs Gogs Missing Authorization in Attachment Download in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52797
GO-2026-5545
GHSA-pm6v-2h4w-4rp2
Jun 25, 2026
Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52806
GO-2026-5580
GHSA-qf6p-p7ww-cwr9
Jun 25, 2026
Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52800
GO-2026-5556
GHSA-pwx3-qcgw-vh7h
Jun 25, 2026
Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52808
GO-2026-5065
GHSA-268j-37xf-pp52
Jun 25, 2026
Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52798
GO-2026-5477
GHSA-jq8v-rmf6-65jw
Jun 25, 2026
Gogs has Stored XSS in `.ipynb` Preview in gogs.io/gogs Gogs has Stored XSS in NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52805
GO-2026-5387
GHSA-g2f5-gjr4-qjvm
Jun 25, 2026
Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47267
GO-2026-5312
GHSA-c4v7-xg93-qf8g
Jun 25, 2026
Gogs has SSRF in webhook deliveries in gogs.io/gogs Gogs has SSRF in webhook deliveries in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52813
GO-2026-5305
GHSA-c39w-43gm-34h5
Jun 25, 2026
Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5193
GHSA-6vxv-wg6j-5qwp
Jun 25, 2026
Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52815
GO-2026-5202
GHSA-744x-3838-5r56
Jun 25, 2026
Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52812
GO-2026-5184
GHSA-6p9m-q3jp-47h4
Jun 25, 2026
Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52811
GO-2026-5249
GHSA-89mr-xqfv-758m
Jun 25, 2026
Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-64719
GO-2026-5098
GHSA-3qq3-668m-v9mj
Jun 25, 2026
Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52816
GO-2026-5103
GHSA-3w28-36p9-w929
Jun 25, 2026
Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52809
GO-2026-5140
GHSA-5c3f-6486-3g7g
Jun 25, 2026
Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52804
GO-2026-5110
GHSA-4565-r4x7-hg8j
Jun 25, 2026
Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52796
GO-2026-5124
GHSA-4j89-2c4f-44c6
Jun 25, 2026
Gogs has DoS in rendering issue index pattern in gogs.io/gogs Gogs has DoS in rendering issue index pattern in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-25921
GO-2026-4616
GHSA-cj4v-437j-jq4c
Mar 10, 2026
Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26195
GO-2026-4618
GHSA-vgvf-m4fw-938j
Mar 10, 2026
Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26276
GO-2026-4627
GHSA-vgjm-2cpf-4g7c
Mar 10, 2026
Gogs: DOM-based XSS via milestone selection in gogs.io/gogs Gogs: DOM-based XSS via milestone selection in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26022
GO-2026-4620
GHSA-xrcr-gmf5-2r8j
Mar 10, 2026
Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26194
GO-2026-4617
GHSA-v9vm-r24h-6rqm
Mar 10, 2026
Gogs: Release tag option injection in release deletion in gogs.io/gogs Gogs: Release tag option injection in release deletion in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26196
GO-2026-4619
GHSA-x9p5-w45c-7ffc
Mar 10, 2026
Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-25229
GO-2026-4499
GHSA-cv22-72px-f4gh
Feb 23, 2026
Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25232
GO-2026-4498
GHSA-2c6v-8r3v-gh6p
Feb 23, 2026
Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.1. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25120
GO-2026-4501
GHSA-jj5m-h57j-5gv7
Feb 23, 2026
Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25242
GO-2026-4500
GHSA-fc3h-92p8-h36f
Feb 23, 2026
Unauthenticated File Upload in Gogs in gogs.io/gogs Unauthenticated File Upload in Gogs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.1. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-23632
GO-2026-4450
GHSA-5qhx-gwfj-6jqr
Feb 17, 2026
Gogs user can update repository content with read-only permission in gogs.io/gogs Gogs user can update repository content with read-only permission in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4454
GHSA-26gq-grmh-6xm6
Feb 17, 2026
Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References
Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-64175
GO-2026-4449
GHSA-p6x6-9mx6-26wj
Feb 17, 2026
Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-23633
GO-2026-4453
GHSA-mrph-w4hh-gx3g
Feb 17, 2026
Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24135
GO-2026-4452
GHSA-jp7c-wj6q-3qf2
Feb 17, 2026
Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65852
GO-2026-4457
GHSA-rjv5-9px2-fqw6
Feb 17, 2026
Gogs has authorization bypass in repository deletion API in gogs.io/gogs Gogs has authorization bypass in repository deletion API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-64111
GO-2026-4448
GHSA-gg64-xxr9-qhjp
Feb 17, 2026
Gogs's update .git/config file allows remote command execution in gogs.io/gogs Gogs's update .git/config file allows remote command execution in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-22592
GO-2026-4451
GHSA-cr88-6mqm-4g57
Feb 17, 2026
Gogs has a Denial of Service issue in gogs.io/gogs Gogs has a Denial of Service issue in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References
Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-8110
GO-2025-4225
GHSA-mq8m-42gh-wq7r
Dec 15, 2025
Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-47943
GO-2025-3778
GHSA-xh32-cx6c-cp4v
Jul 28, 2025
Gogs XSS allowed by stored call in PDF renderer in gogs.io/gogs Gogs XSS allowed by stored call in PDF renderer in gogs.io/gogs Fixed in
0.13.3-0.20250608224432-110117b2e5e5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-56731
GO-2025-3776
GHSA-wj44-9vcg-wjq7
Jul 28, 2025
Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs Fixed in
0.13.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-55947
GO-2024-3356
GHSA-qf5v-rp47-55gg
Jan 07, 2025
Path Traversal in file update API in gogs in gogs.io/gogs Path Traversal in file update API in gogs in gogs.io/gogs Fixed in
0.13.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-54148
GO-2024-3355
GHSA-r7j8-5h9c-f6fx
Jan 07, 2025
Remote Command Execution in file editing in gogs in gogs.io/gogs Remote Command Execution in file editing in gogs in gogs.io/gogs Fixed in
0.13.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39930
GHSA-vm62-9jw3-c8w3
GHSA-p69r-v3h4-rj4f
GO-2024-2969
Dec 23, 2024
Gogs has an argument Injection in the built-in SSH server
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhen the built-in SSH server is enabled ( PatchesThe WorkaroundsDisable the use of built-in SSH server on operating systems other than Windows. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39930 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39932
GHSA-9pp6-wq8c-3w2c
GHSA-hf29-9hfh-w63j
GO-2024-2971
Dec 23, 2024
Gogs allows argument injection during the previewing of changes
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactUnprivileged user accounts can write to arbitrary files on the filesystem. We could demonstrate its exploitation to force a re-installation of the instance, granting administrator rights. It allows accessing and altering any user's code hosted on the same instance. PatchesUnintended Git options has been ignored for diff preview (https://github.com/gogs/gogs/pull/7871). Users should upgrade to 0.13.1 or the latest 0.14.0+dev. WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39932 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39931
GHSA-ccqv-43vm-4f3w
GHSA-2vgj-3pvg-xh4w
GO-2024-2970
Dec 23, 2024
Gogs allows deletion of internal files
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactUnprivileged user accounts can execute arbitrary commands on the Gogs instance with the privileges of the account specified by PatchesDeletion of WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39931 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39933
GHSA-m27m-h5gj-wwmg
GHSA-8mm6-wmpp-mmm3
GO-2024-2972
Dec 23, 2024
Gogs allows argument Injection when tagging new releases
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactUnprivileged user accounts with at least one SSH key can read arbitrary files on the system. For instance, they could leak the configuration files that could contain database credentials ( PatchesUnintended Git options has been ignored for creating tags (https://github.com/gogs/gogs/pull/7872). Users should upgrade to 0.13.1 or the latest 0.14.0+dev. WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39933 Fixed in
0.13.1
References
Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-44625
GO-2024-3275
GHSA-phm4-wf3h-pc3r
Nov 19, 2024
Unpatched Remote Code Execution in Gogs in gogs.io/gogs Unpatched Remote Code Execution in Gogs in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-32174
GO-2022-1060
GHSA-mcjj-2fvq-mc3r
Aug 21, 2024
Gogs vulnerable to Cross-site Scripting in gogs.io/gogs Gogs vulnerable to Cross-site Scripting in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1884
GO-2022-0749
GHSA-958j-443g-7mm7
Aug 21, 2024
OS Command Injection in gogs in gogs.io/gogs OS Command Injection in gogs in gogs.io/gogs Fixed in
0.12.8
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1285
GO-2022-0583
GHSA-w689-557m-2cvq
Aug 21, 2024
Server-Side Request Forgery in gogs webhook in gogs.io/gogs Server-Side Request Forgery in gogs webhook in gogs.io/gogs Fixed in
0.12.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1464
GO-2022-0597
GHSA-ff28-f46g-r9g8
Aug 21, 2024
Cross-site Scripting in Gogs in gogs.io/gogs Cross-site Scripting in Gogs in gogs.io/gogs Fixed in
0.12.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1992
GO-2022-0570
GHSA-994f-7g86-qr56
Aug 21, 2024
Path Traversal in file editor on Windows in Gogs in gogs.io/gogs Path Traversal in file editor on Windows in Gogs in gogs.io/gogs Fixed in
0.12.9
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1986
GO-2022-0556
GHSA-67mx-jc2f-jgjm
Aug 21, 2024
OS Command Injection in file editor in Gogs in gogs.io/gogs OS Command Injection in file editor in Gogs in gogs.io/gogs Fixed in
0.12.9
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1993
GO-2022-0562
GHSA-6vcc-v9vw-g2x5
Aug 21, 2024
Path Traversal in Git HTTP endpoints in Gogs in gogs.io/gogs Path Traversal in Git HTTP endpoints in Gogs in gogs.io/gogs Fixed in
0.12.9
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0473
GHSA-pj96-4jhv-v792
Aug 21, 2024
Cross site scripting via cookies in gogs in gogs.io/gogs Cross site scripting via cookies in gogs in gogs.io/gogs Fixed in
0.12.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31038
GO-2022-0483
GHSA-xq4v-vrp9-vcf2
Aug 21, 2024
Cross-site Scripting vulnerability in repository issue list in Gogs in gogs.io/gogs Cross-site Scripting vulnerability in repository issue list in Gogs in gogs.io/gogs Fixed in
0.12.9
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-32546
GO-2022-0471
GHSA-56j7-2pm8-rgmx
Aug 21, 2024
OS Command Injection in gogs in gogs.io/gogs OS Command Injection in gogs in gogs.io/gogs Fixed in
0.12.8
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2024
GO-2023-1596
GHSA-pfvh-p8qp-9ww9
Aug 20, 2024
Gogs OS Command Injection vulnerability in gogs.io/gogs Gogs OS Command Injection vulnerability in gogs.io/gogs Fixed in
0.12.11
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.12.7-rc.1
pre
Dependencies (49)
+ 41 more |
|
v0.12.6
initial
63 CVEs
CVE-2026-52802
GO-2026-5773
GHSA-xxhq-69mf-w8cr
Jun 25, 2026
Gogs has an Open Redirect via redirect_to in gogs.io/gogs Gogs has an Open Redirect via redirect_to in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52814
GO-2026-5765
GHSA-xp79-5mx3-jx52
Jun 25, 2026
Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52801
GO-2026-5724
GHSA-wv27-2vqp-j7g5
Jun 25, 2026
Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-25119
GO-2026-5695
GHSA-w6j9-vw59-27wv
Jun 25, 2026
Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52810
GO-2026-5712
GHSA-wmfg-5p4h-5fw3
Jun 25, 2026
Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52807
GO-2026-5661
GHSA-vcm5-gvmp-78mp
Jun 25, 2026
Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52799
GO-2026-5536
GHSA-p9f5-h3rx-j5qw
Jun 25, 2026
Gogs Missing Authorization in Attachment Download in gogs.io/gogs Gogs Missing Authorization in Attachment Download in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52797
GO-2026-5545
GHSA-pm6v-2h4w-4rp2
Jun 25, 2026
Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52806
GO-2026-5580
GHSA-qf6p-p7ww-cwr9
Jun 25, 2026
Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52800
GO-2026-5556
GHSA-pwx3-qcgw-vh7h
Jun 25, 2026
Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52808
GO-2026-5065
GHSA-268j-37xf-pp52
Jun 25, 2026
Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52798
GO-2026-5477
GHSA-jq8v-rmf6-65jw
Jun 25, 2026
Gogs has Stored XSS in `.ipynb` Preview in gogs.io/gogs Gogs has Stored XSS in NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52805
GO-2026-5387
GHSA-g2f5-gjr4-qjvm
Jun 25, 2026
Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47267
GO-2026-5312
GHSA-c4v7-xg93-qf8g
Jun 25, 2026
Gogs has SSRF in webhook deliveries in gogs.io/gogs Gogs has SSRF in webhook deliveries in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52813
GO-2026-5305
GHSA-c39w-43gm-34h5
Jun 25, 2026
Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5193
GHSA-6vxv-wg6j-5qwp
Jun 25, 2026
Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52815
GO-2026-5202
GHSA-744x-3838-5r56
Jun 25, 2026
Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52812
GO-2026-5184
GHSA-6p9m-q3jp-47h4
Jun 25, 2026
Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52811
GO-2026-5249
GHSA-89mr-xqfv-758m
Jun 25, 2026
Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-64719
GO-2026-5098
GHSA-3qq3-668m-v9mj
Jun 25, 2026
Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52816
GO-2026-5103
GHSA-3w28-36p9-w929
Jun 25, 2026
Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52809
GO-2026-5140
GHSA-5c3f-6486-3g7g
Jun 25, 2026
Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52804
GO-2026-5110
GHSA-4565-r4x7-hg8j
Jun 25, 2026
Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52796
GO-2026-5124
GHSA-4j89-2c4f-44c6
Jun 25, 2026
Gogs has DoS in rendering issue index pattern in gogs.io/gogs Gogs has DoS in rendering issue index pattern in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-25921
GO-2026-4616
GHSA-cj4v-437j-jq4c
Mar 10, 2026
Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26195
GO-2026-4618
GHSA-vgvf-m4fw-938j
Mar 10, 2026
Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26276
GO-2026-4627
GHSA-vgjm-2cpf-4g7c
Mar 10, 2026
Gogs: DOM-based XSS via milestone selection in gogs.io/gogs Gogs: DOM-based XSS via milestone selection in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26022
GO-2026-4620
GHSA-xrcr-gmf5-2r8j
Mar 10, 2026
Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26194
GO-2026-4617
GHSA-v9vm-r24h-6rqm
Mar 10, 2026
Gogs: Release tag option injection in release deletion in gogs.io/gogs Gogs: Release tag option injection in release deletion in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26196
GO-2026-4619
GHSA-x9p5-w45c-7ffc
Mar 10, 2026
Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-25229
GO-2026-4499
GHSA-cv22-72px-f4gh
Feb 23, 2026
Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25232
GO-2026-4498
GHSA-2c6v-8r3v-gh6p
Feb 23, 2026
Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.1. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25120
GO-2026-4501
GHSA-jj5m-h57j-5gv7
Feb 23, 2026
Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25242
GO-2026-4500
GHSA-fc3h-92p8-h36f
Feb 23, 2026
Unauthenticated File Upload in Gogs in gogs.io/gogs Unauthenticated File Upload in Gogs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.1. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-23632
GO-2026-4450
GHSA-5qhx-gwfj-6jqr
Feb 17, 2026
Gogs user can update repository content with read-only permission in gogs.io/gogs Gogs user can update repository content with read-only permission in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4454
GHSA-26gq-grmh-6xm6
Feb 17, 2026
Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References
Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-64175
GO-2026-4449
GHSA-p6x6-9mx6-26wj
Feb 17, 2026
Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-23633
GO-2026-4453
GHSA-mrph-w4hh-gx3g
Feb 17, 2026
Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24135
GO-2026-4452
GHSA-jp7c-wj6q-3qf2
Feb 17, 2026
Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65852
GO-2026-4457
GHSA-rjv5-9px2-fqw6
Feb 17, 2026
Gogs has authorization bypass in repository deletion API in gogs.io/gogs Gogs has authorization bypass in repository deletion API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-64111
GO-2026-4448
GHSA-gg64-xxr9-qhjp
Feb 17, 2026
Gogs's update .git/config file allows remote command execution in gogs.io/gogs Gogs's update .git/config file allows remote command execution in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-22592
GO-2026-4451
GHSA-cr88-6mqm-4g57
Feb 17, 2026
Gogs has a Denial of Service issue in gogs.io/gogs Gogs has a Denial of Service issue in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References
Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-8110
GO-2025-4225
GHSA-mq8m-42gh-wq7r
Dec 15, 2025
Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-47943
GO-2025-3778
GHSA-xh32-cx6c-cp4v
Jul 28, 2025
Gogs XSS allowed by stored call in PDF renderer in gogs.io/gogs Gogs XSS allowed by stored call in PDF renderer in gogs.io/gogs Fixed in
0.13.3-0.20250608224432-110117b2e5e5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-56731
GO-2025-3776
GHSA-wj44-9vcg-wjq7
Jul 28, 2025
Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs Fixed in
0.13.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-55947
GO-2024-3356
GHSA-qf5v-rp47-55gg
Jan 07, 2025
Path Traversal in file update API in gogs in gogs.io/gogs Path Traversal in file update API in gogs in gogs.io/gogs Fixed in
0.13.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-54148
GO-2024-3355
GHSA-r7j8-5h9c-f6fx
Jan 07, 2025
Remote Command Execution in file editing in gogs in gogs.io/gogs Remote Command Execution in file editing in gogs in gogs.io/gogs Fixed in
0.13.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39930
GHSA-vm62-9jw3-c8w3
GHSA-p69r-v3h4-rj4f
GO-2024-2969
Dec 23, 2024
Gogs has an argument Injection in the built-in SSH server
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhen the built-in SSH server is enabled ( PatchesThe WorkaroundsDisable the use of built-in SSH server on operating systems other than Windows. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39930 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39932
GHSA-9pp6-wq8c-3w2c
GHSA-hf29-9hfh-w63j
GO-2024-2971
Dec 23, 2024
Gogs allows argument injection during the previewing of changes
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactUnprivileged user accounts can write to arbitrary files on the filesystem. We could demonstrate its exploitation to force a re-installation of the instance, granting administrator rights. It allows accessing and altering any user's code hosted on the same instance. PatchesUnintended Git options has been ignored for diff preview (https://github.com/gogs/gogs/pull/7871). Users should upgrade to 0.13.1 or the latest 0.14.0+dev. WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39932 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39931
GHSA-ccqv-43vm-4f3w
GHSA-2vgj-3pvg-xh4w
GO-2024-2970
Dec 23, 2024
Gogs allows deletion of internal files
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactUnprivileged user accounts can execute arbitrary commands on the Gogs instance with the privileges of the account specified by PatchesDeletion of WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39931 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39933
GHSA-m27m-h5gj-wwmg
GHSA-8mm6-wmpp-mmm3
GO-2024-2972
Dec 23, 2024
Gogs allows argument Injection when tagging new releases
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactUnprivileged user accounts with at least one SSH key can read arbitrary files on the system. For instance, they could leak the configuration files that could contain database credentials ( PatchesUnintended Git options has been ignored for creating tags (https://github.com/gogs/gogs/pull/7872). Users should upgrade to 0.13.1 or the latest 0.14.0+dev. WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39933 Fixed in
0.13.1
References
Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-44625
GO-2024-3275
GHSA-phm4-wf3h-pc3r
Nov 19, 2024
Unpatched Remote Code Execution in Gogs in gogs.io/gogs Unpatched Remote Code Execution in Gogs in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-32174
GO-2022-1060
GHSA-mcjj-2fvq-mc3r
Aug 21, 2024
Gogs vulnerable to Cross-site Scripting in gogs.io/gogs Gogs vulnerable to Cross-site Scripting in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1884
GO-2022-0749
GHSA-958j-443g-7mm7
Aug 21, 2024
OS Command Injection in gogs in gogs.io/gogs OS Command Injection in gogs in gogs.io/gogs Fixed in
0.12.8
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1285
GO-2022-0583
GHSA-w689-557m-2cvq
Aug 21, 2024
Server-Side Request Forgery in gogs webhook in gogs.io/gogs Server-Side Request Forgery in gogs webhook in gogs.io/gogs Fixed in
0.12.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1464
GO-2022-0597
GHSA-ff28-f46g-r9g8
Aug 21, 2024
Cross-site Scripting in Gogs in gogs.io/gogs Cross-site Scripting in Gogs in gogs.io/gogs Fixed in
0.12.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1992
GO-2022-0570
GHSA-994f-7g86-qr56
Aug 21, 2024
Path Traversal in file editor on Windows in Gogs in gogs.io/gogs Path Traversal in file editor on Windows in Gogs in gogs.io/gogs Fixed in
0.12.9
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1986
GO-2022-0556
GHSA-67mx-jc2f-jgjm
Aug 21, 2024
OS Command Injection in file editor in Gogs in gogs.io/gogs OS Command Injection in file editor in Gogs in gogs.io/gogs Fixed in
0.12.9
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1993
GO-2022-0562
GHSA-6vcc-v9vw-g2x5
Aug 21, 2024
Path Traversal in Git HTTP endpoints in Gogs in gogs.io/gogs Path Traversal in Git HTTP endpoints in Gogs in gogs.io/gogs Fixed in
0.12.9
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0473
GHSA-pj96-4jhv-v792
Aug 21, 2024
Cross site scripting via cookies in gogs in gogs.io/gogs Cross site scripting via cookies in gogs in gogs.io/gogs Fixed in
0.12.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31038
GO-2022-0483
GHSA-xq4v-vrp9-vcf2
Aug 21, 2024
Cross-site Scripting vulnerability in repository issue list in Gogs in gogs.io/gogs Cross-site Scripting vulnerability in repository issue list in Gogs in gogs.io/gogs Fixed in
0.12.9
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-32546
GO-2022-0471
GHSA-56j7-2pm8-rgmx
Aug 21, 2024
OS Command Injection in gogs in gogs.io/gogs OS Command Injection in gogs in gogs.io/gogs Fixed in
0.12.8
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2024
GO-2023-1596
GHSA-pfvh-p8qp-9ww9
Aug 20, 2024
Gogs OS Command Injection vulnerability in gogs.io/gogs Gogs OS Command Injection vulnerability in gogs.io/gogs Fixed in
0.12.11
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.12.6
initial
Dependencies (49)
+ 41 more |
|
v0.12.6-rc.1
pre
64 CVEs
CVE-2026-52802
GO-2026-5773
GHSA-xxhq-69mf-w8cr
Jun 25, 2026
Gogs has an Open Redirect via redirect_to in gogs.io/gogs Gogs has an Open Redirect via redirect_to in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52814
GO-2026-5765
GHSA-xp79-5mx3-jx52
Jun 25, 2026
Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52801
GO-2026-5724
GHSA-wv27-2vqp-j7g5
Jun 25, 2026
Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-25119
GO-2026-5695
GHSA-w6j9-vw59-27wv
Jun 25, 2026
Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52810
GO-2026-5712
GHSA-wmfg-5p4h-5fw3
Jun 25, 2026
Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52807
GO-2026-5661
GHSA-vcm5-gvmp-78mp
Jun 25, 2026
Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52799
GO-2026-5536
GHSA-p9f5-h3rx-j5qw
Jun 25, 2026
Gogs Missing Authorization in Attachment Download in gogs.io/gogs Gogs Missing Authorization in Attachment Download in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52797
GO-2026-5545
GHSA-pm6v-2h4w-4rp2
Jun 25, 2026
Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52806
GO-2026-5580
GHSA-qf6p-p7ww-cwr9
Jun 25, 2026
Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52800
GO-2026-5556
GHSA-pwx3-qcgw-vh7h
Jun 25, 2026
Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52808
GO-2026-5065
GHSA-268j-37xf-pp52
Jun 25, 2026
Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52798
GO-2026-5477
GHSA-jq8v-rmf6-65jw
Jun 25, 2026
Gogs has Stored XSS in `.ipynb` Preview in gogs.io/gogs Gogs has Stored XSS in NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52805
GO-2026-5387
GHSA-g2f5-gjr4-qjvm
Jun 25, 2026
Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47267
GO-2026-5312
GHSA-c4v7-xg93-qf8g
Jun 25, 2026
Gogs has SSRF in webhook deliveries in gogs.io/gogs Gogs has SSRF in webhook deliveries in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52813
GO-2026-5305
GHSA-c39w-43gm-34h5
Jun 25, 2026
Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5193
GHSA-6vxv-wg6j-5qwp
Jun 25, 2026
Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52815
GO-2026-5202
GHSA-744x-3838-5r56
Jun 25, 2026
Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52812
GO-2026-5184
GHSA-6p9m-q3jp-47h4
Jun 25, 2026
Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52811
GO-2026-5249
GHSA-89mr-xqfv-758m
Jun 25, 2026
Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-64719
GO-2026-5098
GHSA-3qq3-668m-v9mj
Jun 25, 2026
Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52816
GO-2026-5103
GHSA-3w28-36p9-w929
Jun 25, 2026
Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52809
GO-2026-5140
GHSA-5c3f-6486-3g7g
Jun 25, 2026
Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52804
GO-2026-5110
GHSA-4565-r4x7-hg8j
Jun 25, 2026
Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-52796
GO-2026-5124
GHSA-4j89-2c4f-44c6
Jun 25, 2026
Gogs has DoS in rendering issue index pattern in gogs.io/gogs Gogs has DoS in rendering issue index pattern in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.3. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-25921
GO-2026-4616
GHSA-cj4v-437j-jq4c
Mar 10, 2026
Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26195
GO-2026-4618
GHSA-vgvf-m4fw-938j
Mar 10, 2026
Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26276
GO-2026-4627
GHSA-vgjm-2cpf-4g7c
Mar 10, 2026
Gogs: DOM-based XSS via milestone selection in gogs.io/gogs Gogs: DOM-based XSS via milestone selection in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26022
GO-2026-4620
GHSA-xrcr-gmf5-2r8j
Mar 10, 2026
Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26194
GO-2026-4617
GHSA-v9vm-r24h-6rqm
Mar 10, 2026
Gogs: Release tag option injection in release deletion in gogs.io/gogs Gogs: Release tag option injection in release deletion in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.2. References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-26196
GO-2026-4619
GHSA-x9p5-w45c-7ffc
Mar 10, 2026
Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-25229
GO-2026-4499
GHSA-cv22-72px-f4gh
Feb 23, 2026
Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25232
GO-2026-4498
GHSA-2c6v-8r3v-gh6p
Feb 23, 2026
Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.1. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25120
GO-2026-4501
GHSA-jj5m-h57j-5gv7
Feb 23, 2026
Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-25242
GO-2026-4500
GHSA-fc3h-92p8-h36f
Feb 23, 2026
Unauthenticated File Upload in Gogs in gogs.io/gogs Unauthenticated File Upload in Gogs in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.1. References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-23632
GO-2026-4450
GHSA-5qhx-gwfj-6jqr
Feb 17, 2026
Gogs user can update repository content with read-only permission in gogs.io/gogs Gogs user can update repository content with read-only permission in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4454
GHSA-26gq-grmh-6xm6
Feb 17, 2026
Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References
Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-64175
GO-2026-4449
GHSA-p6x6-9mx6-26wj
Feb 17, 2026
Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-23633
GO-2026-4453
GHSA-mrph-w4hh-gx3g
Feb 17, 2026
Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24135
GO-2026-4452
GHSA-jp7c-wj6q-3qf2
Feb 17, 2026
Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-65852
GO-2026-4457
GHSA-rjv5-9px2-fqw6
Feb 17, 2026
Gogs has authorization bypass in repository deletion API in gogs.io/gogs Gogs has authorization bypass in repository deletion API in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-64111
GO-2026-4448
GHSA-gg64-xxr9-qhjp
Feb 17, 2026
Gogs's update .git/config file allows remote command execution in gogs.io/gogs Gogs's update .git/config file allows remote command execution in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-22592
GO-2026-4451
GHSA-cr88-6mqm-4g57
Feb 17, 2026
Gogs has a Denial of Service issue in gogs.io/gogs Gogs has a Denial of Service issue in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4. References
Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-8110
GO-2025-4225
GHSA-mq8m-42gh-wq7r
Dec 15, 2025
Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-47943
GO-2025-3778
GHSA-xh32-cx6c-cp4v
Jul 28, 2025
Gogs XSS allowed by stored call in PDF renderer in gogs.io/gogs Gogs XSS allowed by stored call in PDF renderer in gogs.io/gogs Fixed in
0.13.3-0.20250608224432-110117b2e5e5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-56731
GO-2025-3776
GHSA-wj44-9vcg-wjq7
Jul 28, 2025
Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs Fixed in
0.13.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-55947
GO-2024-3356
GHSA-qf5v-rp47-55gg
Jan 07, 2025
Path Traversal in file update API in gogs in gogs.io/gogs Path Traversal in file update API in gogs in gogs.io/gogs Fixed in
0.13.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-54148
GO-2024-3355
GHSA-r7j8-5h9c-f6fx
Jan 07, 2025
Remote Command Execution in file editing in gogs in gogs.io/gogs Remote Command Execution in file editing in gogs in gogs.io/gogs Fixed in
0.13.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-39930
GHSA-vm62-9jw3-c8w3
GHSA-p69r-v3h4-rj4f
GO-2024-2969
Dec 23, 2024
Gogs has an argument Injection in the built-in SSH server
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhen the built-in SSH server is enabled ( PatchesThe WorkaroundsDisable the use of built-in SSH server on operating systems other than Windows. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39930 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39932
GHSA-9pp6-wq8c-3w2c
GHSA-hf29-9hfh-w63j
GO-2024-2971
Dec 23, 2024
Gogs allows argument injection during the previewing of changes
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactUnprivileged user accounts can write to arbitrary files on the filesystem. We could demonstrate its exploitation to force a re-installation of the instance, granting administrator rights. It allows accessing and altering any user's code hosted on the same instance. PatchesUnintended Git options has been ignored for diff preview (https://github.com/gogs/gogs/pull/7871). Users should upgrade to 0.13.1 or the latest 0.14.0+dev. WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39932 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39931
GHSA-ccqv-43vm-4f3w
GHSA-2vgj-3pvg-xh4w
GO-2024-2970
Dec 23, 2024
Gogs allows deletion of internal files
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactUnprivileged user accounts can execute arbitrary commands on the Gogs instance with the privileges of the account specified by PatchesDeletion of WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39931 Fixed in
0.13.1
References Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-39933
GHSA-m27m-h5gj-wwmg
GHSA-8mm6-wmpp-mmm3
GO-2024-2972
Dec 23, 2024
Gogs allows argument Injection when tagging new releases
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactUnprivileged user accounts with at least one SSH key can read arbitrary files on the system. For instance, they could leak the configuration files that could contain database credentials ( PatchesUnintended Git options has been ignored for creating tags (https://github.com/gogs/gogs/pull/7872). Users should upgrade to 0.13.1 or the latest 0.14.0+dev. WorkaroundsNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions. Referenceshttps://www.cve.org/CVERecord?id=CVE-2024-39933 Fixed in
0.13.1
References
Updated Dec 23, 2024 · Source: OSV.dev
CVE-2024-44625
GO-2024-3275
GHSA-phm4-wf3h-pc3r
Nov 19, 2024
Unpatched Remote Code Execution in Gogs in gogs.io/gogs Unpatched Remote Code Execution in Gogs in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-32174
GO-2022-1060
GHSA-mcjj-2fvq-mc3r
Aug 21, 2024
Gogs vulnerable to Cross-site Scripting in gogs.io/gogs Gogs vulnerable to Cross-site Scripting in gogs.io/gogs References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1884
GO-2022-0749
GHSA-958j-443g-7mm7
Aug 21, 2024
OS Command Injection in gogs in gogs.io/gogs OS Command Injection in gogs in gogs.io/gogs Fixed in
0.12.8
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1285
GO-2022-0583
GHSA-w689-557m-2cvq
Aug 21, 2024
Server-Side Request Forgery in gogs webhook in gogs.io/gogs Server-Side Request Forgery in gogs webhook in gogs.io/gogs Fixed in
0.12.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1464
GO-2022-0597
GHSA-ff28-f46g-r9g8
Aug 21, 2024
Cross-site Scripting in Gogs in gogs.io/gogs Cross-site Scripting in Gogs in gogs.io/gogs Fixed in
0.12.7
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1992
GO-2022-0570
GHSA-994f-7g86-qr56
Aug 21, 2024
Path Traversal in file editor on Windows in Gogs in gogs.io/gogs Path Traversal in file editor on Windows in Gogs in gogs.io/gogs Fixed in
0.12.9
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-0415
GO-2022-0554
GHSA-5gjh-5j4f-cpwv
Aug 21, 2024
Unrestricted Upload of File with Dangerous Type in Gogs in gogs.io/gogs Unrestricted Upload of File with Dangerous Type in Gogs in gogs.io/gogs Fixed in
0.12.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1986
GO-2022-0556
GHSA-67mx-jc2f-jgjm
Aug 21, 2024
OS Command Injection in file editor in Gogs in gogs.io/gogs OS Command Injection in file editor in Gogs in gogs.io/gogs Fixed in
0.12.9
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-1993
GO-2022-0562
GHSA-6vcc-v9vw-g2x5
Aug 21, 2024
Path Traversal in Git HTTP endpoints in Gogs in gogs.io/gogs Path Traversal in Git HTTP endpoints in Gogs in gogs.io/gogs Fixed in
0.12.9
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0473
GHSA-pj96-4jhv-v792
Aug 21, 2024
Cross site scripting via cookies in gogs in gogs.io/gogs Cross site scripting via cookies in gogs in gogs.io/gogs Fixed in
0.12.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-31038
GO-2022-0483
GHSA-xq4v-vrp9-vcf2
Aug 21, 2024
Cross-site Scripting vulnerability in repository issue list in Gogs in gogs.io/gogs Cross-site Scripting vulnerability in repository issue list in Gogs in gogs.io/gogs Fixed in
0.12.9
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-32546
GO-2022-0471
GHSA-56j7-2pm8-rgmx
Aug 21, 2024
OS Command Injection in gogs in gogs.io/gogs OS Command Injection in gogs in gogs.io/gogs Fixed in
0.12.8
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-2024
GO-2023-1596
GHSA-pfvh-p8qp-9ww9
Aug 20, 2024
Gogs OS Command Injection vulnerability in gogs.io/gogs Gogs OS Command Injection vulnerability in gogs.io/gogs Fixed in
0.12.11
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.12.6-rc.1
pre
Dependencies (49)
+ 41 more |