Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.5 CVE-2026-52799

Gogs: Missing Authorization in Attachment Download_CVE-2026-52799

Gogs is an open source self-hosted Git service. Prior to 0.14.3, GET /attachments/:uuid returns the raw attachment file without verifying whether t...

gogs gogs < 0.14.3 CVE
HIGH 8.9 CVE-2026-52798

Gogs: Stored XSS in `.ipynb` Preview_CVE-2026-52798

Gogs is an open source self-hosted Git service. Prior to 0.14.3, although .ipynb previews are sanitized on the server side via /-/api/sanitize_ipyn...

gogs gogs < 0.14.3 CVE
HIGH 7.5 CVE-2026-50129

Mastodon: Persistent anonymous DoS via unhandled NoMethodError in MATH_TRANSFORMER_CVE-2026-50129

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.11, 4.4.18, and 4.3.24, a DoS can be triggered by (Uncaugh...

mastodon mastodon >= 4.5.0-beta.1, < 4.5.11 CVE
HIGH 8.3 CVE-2026-47267

Gogs: SSRF in webhook deliveries_CVE-2026-47267

Gogs is an open source self-hosted Git service. Prior to 0.14.3, the fix for CVE-2022-1285 prevents adding webooks or running webhooks with URLs wi...

gogs gogs < 0.14.3 CVE
HIGH 7.7 CVE-2026-25119

Gogs: Authentication Bypass via Unvalidated Reverse Proxy Headers_CVE-2026-25119

Gogs is an open source self-hosted Git service. Prior to 0.14.3, when ENABLE_REVERSE_PROXY_AUTHENTICATION is enabled, Gogs accepts the configured a...

gogs gogs < 0.14.3 CVE
HIGH 8.7 CVE-2026-1840

Missing authentication for critical function in Hubbell Aclara Metrum Cellular Web Interface_CVE-2026-1840

The Aclara Metrum Cellular Web Interface is vulnerable to unauthorized access due to the absence of authentication controls on critical system func...

Hubbell Aclara Metrum Cellular Web Interface CVE
HIGH 7.1 CVE-2026-52812

Gogs: LFS dedupe path leaks private repo content across tenants_CVE-2026-52812

Gogs is an open source self-hosted Git service. Prior to 0.14.3, Git LFS storage is content-addressed by OID alone (///) but per-repo authorization...

gogs gogs < 0.14.3 CVE
HIGH 7.1 CVE-2026-52810

Gogs: Write to readonly repositories using receive-pack + service=git-upload-pack confusion_CVE-2026-52810

Gogs is an open source self-hosted Git service. Prior to 0.14.3, Git smart HTTP authorizes POST …/git-receive-pack using the client-supplied servic...

gogs gogs < 0.14.3 CVE
HIGH 7.1 CVE-2026-52808

Gogs: Write-level collaborators can mutate admin-only repository settings via API_CVE-2026-52808

Gogs is an open source self-hosted Git service. Prior to 0.14.3, three API endpoints — PATCH /api/v1/repos/:owner/:repo/issue-tracker, PATCH /api/v...

gogs gogs < 0.14.3 CVE
HIGH 8.5 CVE-2026-52797

Gogs: Overwriting critical files results in a denial of service_CVE-2026-52797

Gogs is an open source self-hosted Git service. Prior to 0.14.0, as an authorized user, an intruder can dictate the value which is passed to the gi...

gogs gogs < 0.14.0 CVE