Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.9 CVE-2026-52806

Gogs: RCE via git rebase –exec argument injection in pull request merge_CVE-2026-52806

Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code Execution (RCE) on the serv...

gogs gogs < 0.14.3 CVE
HIGH 8.7 CVE-2026-52805

Gogs: Migration Redirect Bypass Leads to Internal Repository Theft_CVE-2026-52805

Gogs is an open source self-hosted Git service. Prior to 0.14.3, a Server-Side Request Forgery (SSRF) vulnerability exists in the repository migrat...

gogs gogs < 0.14.3 CVE
MEDIUM 5.5 CVE-2026-52804

Gogs: Privilege Escalation via Collaboration Access Mode Validation_CVE-2026-52804

Gogs is an open source self-hosted Git service. Prior to 0.14.3, a repository admin collaborator can escalate their privileges to owner-level acces...

gogs gogs < 0.14.3 CVE
MEDIUM 5.4 CVE-2026-52802

Gogs: Open Redirect via redirect_to in Gogs_CVE-2026-52802

Gogs is an open source self-hosted Git service. Prior to 0.14.3, an open redirect vulnerability exists in Gogs where attacker-controlled redirect_t...

gogs gogs < 0.14.3 CVE
HIGH 8.1 CVE-2026-52801

Gogs: Ability to import local repositories via Mirror Settings_CVE-2026-52801

Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Gogs Mirror Settings functionality provide an alternative way from the well pr...

gogs gogs < 0.14.3 CVE
HIGH 8.8 CVE-2026-52800

Gogs: CSRF Leading to Organization Owner Takeover_CVE-2026-52800

Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization team member management can be performed via GET requests without CSRF...

gogs gogs < 0.14.3 CVE
HIGH 7.5 CVE-2026-52799

Gogs: Missing Authorization in Attachment Download_CVE-2026-52799

Gogs is an open source self-hosted Git service. Prior to 0.14.3, GET /attachments/:uuid returns the raw attachment file without verifying whether t...

gogs gogs < 0.14.3 CVE
HIGH 8.9 CVE-2026-52798

Gogs: Stored XSS in `.ipynb` Preview_CVE-2026-52798

Gogs is an open source self-hosted Git service. Prior to 0.14.3, although .ipynb previews are sanitized on the server side via /-/api/sanitize_ipyn...

gogs gogs < 0.14.3 CVE
LOW 3.5 CVE-2026-52796

Gogs: DoS in rendering issue index pattern_CVE-2026-52796

Gogs is an open source self-hosted Git service. Prior to 0.14.3, specially crafted issue index pattern can cause a panic when rendering, resulting ...

gogs gogs < 0.14.3 CVE
MEDIUM 4.3 CVE-2026-52795

Gogs: Authorization Bypass in Watch API allows any user to monitor private repository activity_CVE-2026-52795

Gogs is an open source self-hosted Git service. In 0.14.3 and earlier, any authenticated user can watch a private repository they have no access to...

gogs gogs <= 0.14.3 CVE