Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 4.9 CVE-2025-64719

Gogs: Denial of Service in repository/wiki file listing web pages_CVE-2025-64719

Gogs is an open source self-hosted Git service. Prior to 0.14.3, a malicious user with rights to create a new file on a repository or wiki page can...

gogs gogs < 0.14.3 CVE
CRITICAL 10 CVE-2026-52813

Gogs: Path Traversal in organization name results in RCE through Git hooks_CVE-2026-52813

Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization names containing path traversal sequences (../) are accepted by Gogs,...

gogs gogs < 0.14.3 CVE
HIGH 7.1 CVE-2026-52812

Gogs: LFS dedupe path leaks private repo content across tenants_CVE-2026-52812

Gogs is an open source self-hosted Git service. Prior to 0.14.3, Git LFS storage is content-addressed by OID alone (///) but per-repo authorization...

gogs gogs < 0.14.3 CVE
CRITICAL 9 CVE-2026-52811

Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym_CVE-2026-52811

Gogs is an open source self-hosted Git service. Prior to 0.14.3, (*Repository).UploadRepoFiles checks for symlinks only on the leaf of the upload t...

gogs gogs < 0.14.3 CVE
HIGH 7.1 CVE-2026-52810

Gogs: Write to readonly repositories using receive-pack + service=git-upload-pack confusion_CVE-2026-52810

Gogs is an open source self-hosted Git service. Prior to 0.14.3, Git smart HTTP authorizes POST …/git-receive-pack using the client-supplied servic...

gogs gogs < 0.14.3 CVE
MEDIUM 6.8 CVE-2026-52809

Gogs: Password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES_CVE-2026-52809

Gogs is an open source self-hosted Git service. Prior to 0.14.3, password-reset tokens are generated using conf.Auth.ActivateCodeLives (the account...

gogs gogs < 0.14.3 CVE
HIGH 7.1 CVE-2026-52808

Gogs: Write-level collaborators can mutate admin-only repository settings via API_CVE-2026-52808

Gogs is an open source self-hosted Git service. Prior to 0.14.3, three API endpoints — PATCH /api/v1/repos/:owner/:repo/issue-tracker, PATCH /api/v...

gogs gogs < 0.14.3 CVE
HIGH 8.5 CVE-2026-52797

Gogs: Overwriting critical files results in a denial of service_CVE-2026-52797

Gogs is an open source self-hosted Git service. Prior to 0.14.0, as an authorized user, an intruder can dictate the value which is passed to the gi...

gogs gogs < 0.14.0 CVE
MEDIUM 6.7 CVE-2026-49278

Rocket.Chat: Livechat Visitor Profile Disclosure Leaks Bearer Token and Enables Visitor Impersonation_CVE-2026-49278

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7...

RocketChat Rocket.Chat >= 8.5.0-rc.0, < 8.5.0 CVE
LOW 2.3 CVE-2026-49277

Rocket.Chat: OAuth access and refresh tokens remain valid after account deactivation_CVE-2026-49277

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7...

RocketChat Rocket.Chat >= 8.5.0-rc.0, < 8.5.0 CVE