CVEs we hold for Gogs
Records whose assigning authority named Gogs as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-52816Gogs: Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSSgogs CVE-2026-52815Gogs: Unauthenticated Organization Teams Information Disclosure via APIgogs CVE-2026-52814Gogs: Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion)gogs CVE-2026-52813Gogs: Path Traversal in organization name results in RCE through Git hooksgogs CVE-2026-52812Gogs: LFS dedupe path leaks private repo content across tenantsgogs CVE-2026-52811Gogs: UploadRepoFiles writes outside repo working tree via committed parent symgogs CVE-2026-52810Gogs: Write to readonly repositories using receive-pack + service=git-upload-pack confusiongogs CVE-2026-52809Gogs: Password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVESgogs CVE-2026-52808Gogs: Write-level collaborators can mutate admin-only repository settings via APIgogs CVE-2026-52807Gogs: DOM-based XSS via Milestone Name on New Issue Pagegogs CVE-2026-52806Gogs: RCE via git rebase --exec argument injection in pull request mergegogs CVE-2026-52805Gogs: Migration Redirect Bypass Leads to Internal Repository Theftgogs CVE-2026-52804Gogs: Privilege Escalation via Collaboration Access Mode Validationgogs CVE-2026-52801Gogs: Ability to import local repositories via Mirror Settingsgogs CVE-2026-52797Gogs: Overwriting critical files results in a denial of servicegogs CVE-2026-52795Gogs: Authorization Bypass in Watch API allows any user to monitor private repository activitygogs CVE-2026-26196Gogs: Access tokens get exposed through URL params in API requestsgogs CVE-2026-26195Gogs: Stored XSS in branch and wiki views through author and committer namesgogs CVE-2026-26194Gogs: Release tag option injection in release deletiongogs CVE-2026-25921Gogs: Cross-repository LFS object overwrite via missing content hash verificationgogs CVE-2026-25232Gogs has a Protected Branch Deletion Bypass in Web Interfacegogs CVE-2026-25229Gogs Authorization Bypass Allows Cross-Repository Label Modificationgogs CVE-2026-25120Gogs Allows Cross-Repository Comment Deletion via DeleteCommentgogs CVE-2026-25119Gogs: Authentication Bypass via Unvalidated Reverse Proxy Headersgogs CVE-2026-24135Gogs vulnerable to arbitrary file deletion via path traversal in wiki page updategogs CVE-2026-23633Gogs has arbitrary file read/write via path traversal in Git hook editinggogs CVE-2026-23632Gogs user can update repository content with read-only permissiongogs CVE-2025-64719Gogs: Denial of Service in repository/wiki file listing web pagesgogs CVE-2025-64111Gogs's update .git/config file allows remote command executiongogs CVE-2024-56731Gogs deletion of internal files allows remote command executiongogs CVE-2022-1285Server-Side Request Forgery (SSRF) in gogs/gogsgogs/gogs CVE-2022-0870Server-Side Request Forgery (SSRF) in gogs/gogsgogs/gogs CVE-2022-0415Remote Command Execution in uploading repository file in gogs/gogsgogs/gogs 57 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.