vciy

CVEs we hold for Gogs

Records whose assigning authority named Gogs as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-52816Gogs: Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSSgogs
CVE-2026-52815Gogs: Unauthenticated Organization Teams Information Disclosure via APIgogs
CVE-2026-52814Gogs: Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion)gogs
CVE-2026-52813Gogs: Path Traversal in organization name results in RCE through Git hooksgogs
CVE-2026-52812Gogs: LFS dedupe path leaks private repo content across tenantsgogs
CVE-2026-52811Gogs: UploadRepoFiles writes outside repo working tree via committed parent symgogs
CVE-2026-52810Gogs: Write to readonly repositories using receive-pack + service=git-upload-pack confusiongogs
CVE-2026-52809Gogs: Password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVESgogs
CVE-2026-52808Gogs: Write-level collaborators can mutate admin-only repository settings via APIgogs
CVE-2026-52807Gogs: DOM-based XSS via Milestone Name on New Issue Pagegogs
CVE-2026-52806Gogs: RCE via git rebase --exec argument injection in pull request mergegogs
CVE-2026-52805Gogs: Migration Redirect Bypass Leads to Internal Repository Theftgogs
CVE-2026-52804Gogs: Privilege Escalation via Collaboration Access Mode Validationgogs
CVE-2026-52802Gogs: Open Redirect via redirect_to in Gogsgogs
CVE-2026-52801Gogs: Ability to import local repositories via Mirror Settingsgogs
CVE-2026-52800Gogs: CSRF Leading to Organization Owner Takeovergogs
CVE-2026-52799Gogs: Missing Authorization in Attachment Downloadgogs
CVE-2026-52798Gogs: Stored XSS in `.ipynb` Previewgogs
CVE-2026-52797Gogs: Overwriting critical files results in a denial of servicegogs
CVE-2026-52796Gogs: DoS in rendering issue index patterngogs
CVE-2026-52795Gogs: Authorization Bypass in Watch API allows any user to monitor private repository activitygogs
CVE-2026-47267Gogs: SSRF in webhook deliveriesgogs
CVE-2026-26276Gogs: DOM-based XSS via milestone selectiongogs
CVE-2026-26196Gogs: Access tokens get exposed through URL params in API requestsgogs
CVE-2026-26195Gogs: Stored XSS in branch and wiki views through author and committer namesgogs
CVE-2026-26194Gogs: Release tag option injection in release deletiongogs
CVE-2026-26022Gogs: Stored XSS via data URI in issue commentsgogs
CVE-2026-25921Gogs: Cross-repository LFS object overwrite via missing content hash verificationgogs
CVE-2026-25242Gogs allows unauthenticated file uploadsgogs
CVE-2026-25232Gogs has a Protected Branch Deletion Bypass in Web Interfacegogs
CVE-2026-25229Gogs Authorization Bypass Allows Cross-Repository Label Modificationgogs
CVE-2026-25120Gogs Allows Cross-Repository Comment Deletion via DeleteCommentgogs
CVE-2026-25119Gogs: Authentication Bypass via Unvalidated Reverse Proxy Headersgogs
CVE-2026-24135Gogs vulnerable to arbitrary file deletion via path traversal in wiki page updategogs
CVE-2026-23633Gogs has arbitrary file read/write via path traversal in Git hook editinggogs
CVE-2026-23632Gogs user can update repository content with read-only permissiongogs
CVE-2026-22592Gogs is Vulnerable to Denial of Servicegogs
CVE-2025-8110File overwrite in file update API in GogsGogs
CVE-2025-64719Gogs: Denial of Service in repository/wiki file listing web pagesgogs
CVE-2025-64175Gogs Vulnerable to 2FA Bypass via Recovery Codegogs
CVE-2025-64111Gogs's update .git/config file allows remote command executiongogs
CVE-2025-47943Gogs stored XSS in PDF renderergogs
CVE-2024-56731Gogs deletion of internal files allows remote command executiongogs
CVE-2024-55947Gogs has a Path Traversal in file update APIgogs
CVE-2024-54148Gogs has a Path Traversal in file editing UIgogs
CVE-2022-32174Gogs - XSSgogs
CVE-2022-31038XSS vulnerability in repository issue list in Gogsgogs
CVE-2022-2024OS Command Injection in gogs/gogsgogs/gogs
CVE-2022-1993Path Traversal in gogs/gogsgogs/gogs
CVE-2022-1992Path Traversal in gogs/gogsgogs/gogs
CVE-2022-1986OS Command Injection in gogs/gogsgogs/gogs
CVE-2022-1884Remote Command Execution in gogs/gogsgogs/gogs
CVE-2022-1464Stored xss bug in gogs/gogsgogs/gogs
CVE-2022-1285Server-Side Request Forgery (SSRF) in gogs/gogsgogs/gogs
CVE-2022-0871Missing Authorization in gogs/gogsgogs/gogs
CVE-2022-0870Server-Side Request Forgery (SSRF) in gogs/gogsgogs/gogs
CVE-2022-0415Remote Command Execution in uploading repository file in gogs/gogsgogs/gogs

57 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.