Gogs

Gogs

74 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.03%
  • Veröffentlicht 24.06.2026 20:21:07
  • Zuletzt bearbeitet 26.06.2026 05:16:29

Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code Execution (RCE) on the server by creating a pull request with a specially crafted branch name that injects the --exec flag into th...

  • EPSS 0.5%
  • Veröffentlicht 24.06.2026 20:20:26
  • Zuletzt bearbeitet 26.06.2026 05:16:29

Gogs is an open source self-hosted Git service. Prior to 0.14.3, a repository admin collaborator can escalate their privileges to owner-level access by exploiting an off-by-one error in the ChangeCollaborationAccessMode function. This vulnerability i...

  • EPSS 0.42%
  • Veröffentlicht 24.06.2026 20:19:32
  • Zuletzt bearbeitet 25.06.2026 14:19:40

Gogs is an open source self-hosted Git service. Prior to 0.14.3, GET /attachments/:uuid returns the raw attachment file without verifying whether the requester has view permission for the associated Issue/Comment/Release or the repository. In a test ...

  • EPSS 0.57%
  • Veröffentlicht 24.06.2026 20:18:55
  • Zuletzt bearbeitet 25.06.2026 14:19:40

Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Gogs Mirror Settings functionality provide an alternative way from the well protected New Migration functionality for any authenticated users to import local repositories. This issu...

  • EPSS 0.25%
  • Veröffentlicht 24.06.2026 20:18:11
  • Zuletzt bearbeitet 26.06.2026 05:16:29

Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization team member management can be performed via GET requests without CSRF protection. If a victim who is an organization owner is logged in and is tricked into visiting a craft...

  • EPSS 0.55%
  • Veröffentlicht 24.06.2026 20:17:19
  • Zuletzt bearbeitet 25.06.2026 17:16:40

Gogs is an open source self-hosted Git service. Prior to 0.14.3, an open redirect vulnerability exists in Gogs where attacker-controlled redirect_to parameters can bypass validation, allowing redirection to arbitrary external sites. All redirects in ...

  • EPSS 0.55%
  • Veröffentlicht 24.06.2026 20:15:51
  • Zuletzt bearbeitet 25.06.2026 14:19:40

Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Gogs built-in Go SSH server is vulnerable to an unauthenticated, asymmetric Denial of Service (DoS) attack. The application accepts inbound TCP connections and passes them to golang...

  • EPSS 0.43%
  • Veröffentlicht 24.06.2026 20:14:13
  • Zuletzt bearbeitet 25.06.2026 18:16:39

Gogs is an open source self-hosted Git service. Prior to 0.14.3, although .ipynb previews are sanitized on the server side via /-/api/sanitize_ipynb, the inserted content is re-rendered on the client side without sanitization using marked() on elemen...

  • EPSS 0.28%
  • Veröffentlicht 24.06.2026 20:13:11
  • Zuletzt bearbeitet 25.06.2026 21:16:27

Gogs is an open source self-hosted Git service. Prior to 0.14.3, specially crafted issue index pattern can cause a panic when rendering, resulting in denial of service. In internal/markup/markup.go, RenderIssueIndexPattern renders the issue index pat...

  • EPSS 0.4%
  • Veröffentlicht 24.06.2026 20:09:02
  • Zuletzt bearbeitet 25.06.2026 14:19:40

Gogs is an open source self-hosted Git service. Prior to 0.14.3, the fix for CVE-2022-1285 prevents adding webooks or running webhooks with URLs with a hostname that resolves in localCIDRs. However, webhooks still follow redirects allowing to access ...