Dependency scanning
Check whether gogs.io/gogs is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-52800
Gogs Vulnerable to CSRF Leading to Organization Owner Takeover
CVE-2021-32546
OS Command Injection in gogs
CVE-2026-25119
Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers
CVE-2026-52801
Gogs has the ability to import local repositories via Mirror Settings
CVE-2026-52808
Gogs's write-level collaborators can mutate admin-only repository settings via API
CVE-2026-52810
Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion
CVE-2026-52807
Gogs has DOM-based XSS via Milestone Name on New Issue Page
CVE-2026-52806
Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge
CVE-2026-52802
Gogs has an Open Redirect via redirect_to
CVE-2026-52798
Gogs has Stored XSS in `.ipynb` Preview
CVE-2026-52799
Gogs Missing Authorization in Attachment Download
CVE-2026-52814
Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion)
CVE-2026-52797
Gogs: Overwriting critical files results in a denial of service
CVE-2026-52814
Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs
CVE-2026-52806
Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs
CVE-2026-52800
Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs
CVE-2026-52801
Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs
CVE-2026-52810
Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs
CVE-2026-25119
Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs
CVE-2026-52807
Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs
CVE-2026-52797
Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs
CVE-2026-52799
Gogs Missing Authorization in Attachment Download in gogs.io/gogs
CVE-2026-52798
Gogs has Stored XSS in `.ipynb` Preview in gogs.io/gogs
CVE-2026-52802
Gogs has an Open Redirect via redirect_to in gogs.io/gogs
CVE-2026-52808
Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs
GO-2026-5193
Gogs: XSS in .ipynb files renderer due to outdated notebookjs
CVE-2026-52805
Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft
CVE-2026-47267
Gogs has SSRF in webhook deliveries
CVE-2026-52815
Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API
CVE-2026-52813
Gogs has Path Traversal in organization name that results in RCE through Git hooks
CVE-2026-52812
Gogs: LFS dedupe path leaks private repo content across tenants
CVE-2026-52811
Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym
CVE-2026-52805
Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs
CVE-2026-52813
Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs
CVE-2026-52811
Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs
CVE-2026-47267
Gogs has SSRF in webhook deliveries in gogs.io/gogs
CVE-2026-52815
Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs
GHSA-6vxv-wg6j-5qwp
Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs
CVE-2026-52812
Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs
CVE-2026-52796
Gogs has DoS in rendering issue index pattern
CVE-2026-52809
Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES
CVE-2025-64719
Gogs has a Denial of Service in repository/wiki file listing web pages
CVE-2026-52804
Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation
CVE-2026-52816
Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS
CVE-2026-52809
Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs
CVE-2026-52796
Gogs has DoS in rendering issue index pattern in gogs.io/gogs
CVE-2026-52816
Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs
CVE-2026-52804
Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs
CVE-2025-64719
Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs
CVE-2018-20303
Gogs Directory Traversal
CVE-2026-26194
Gogs: Release tag option injection in release deletion
CVE-2026-26022
Gogs: Stored XSS via data URI in issue comments
CVE-2026-25921
Gogs: Cross-repository LFS object overwrite via missing content hash verification
CVE-2026-26276
Gogs: DOM-based XSS via milestone selection
CVE-2026-26195
Gogs: Stored XSS in branch and wiki views through author and committer names
CVE-2026-26196
Gogs: Access tokens get exposed through URL params in API requests
CVE-2026-26276
Gogs: DOM-based XSS via milestone selection in gogs.io/gogs
CVE-2026-26022
Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs
CVE-2026-26195
Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs
CVE-2026-26194
Gogs: Release tag option injection in release deletion in gogs.io/gogs
CVE-2026-25921
Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs
CVE-2026-26196
Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs
CVE-2025-8110
Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs
CVE-2024-56731
Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs
CVE-2025-47943
Gogs XSS allowed by stored call in PDF renderer in gogs.io/gogs
CVE-2024-54148
Remote Command Execution in file editing in gogs in gogs.io/gogs
CVE-2024-55947
Path Traversal in file update API in gogs in gogs.io/gogs
CVE-2024-44625
Unpatched Remote Code Execution in Gogs in gogs.io/gogs
CVE-2018-15192
Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
CVE-2018-17031
Gogs XSS Vulnerability in gogs.io/gogs
CVE-2022-2024
Gogs OS Command Injection vulnerability in gogs.io/gogs
CVE-2022-32174
Gogs vulnerable to Cross-site Scripting in gogs.io/gogs
CVE-2014-8682
SQL Injection in Gogs in gogs.io/gogs
CVE-2019-14544
Insecure Permissions in Gogs in gogs.io/gogs
GHSA-q347-cg56-pcq4
SSRF in repository migration in gogs.io/gogs
CVE-2018-15178
Open Redirect in gogs.io/gogs
CVE-2020-14958
Insecure Permissions in Gogs in gogs.io/gogs
CVE-2022-1884
OS Command Injection in gogs in gogs.io/gogs
CVE-2014-8683
Cross-site Scripting in Gogs in gogs.io/gogs
CVE-2022-1464
Cross-site Scripting in Gogs in gogs.io/gogs
CVE-2022-0870
SSRF in repository migration in gogs.io/gogs
CVE-2022-1285
Server-Side Request Forgery in gogs webhook in gogs.io/gogs
CVE-2022-1992
Path Traversal in file editor on Windows in Gogs in gogs.io/gogs
CVE-2022-1993
Path Traversal in Git HTTP endpoints in Gogs in gogs.io/gogs
CVE-2022-1986
OS Command Injection in file editor in Gogs in gogs.io/gogs
CVE-2022-0415
Unrestricted Upload of File with Dangerous Type in Gogs in gogs.io/gogs
CVE-2022-31038
Cross-site Scripting vulnerability in repository issue list in Gogs in gogs.io/gogs
CVE-2021-32546
OS Command Injection in gogs in gogs.io/gogs
GHSA-pj96-4jhv-v792
Cross site scripting via cookies in gogs in gogs.io/gogs
CVE-2022-0871
Gogs vulnerable to improper PAM authorization handling in gogs.io/gogs
CVE-2026-25242
Unauthenticated File Upload in Gogs in gogs.io/gogs
CVE-2026-25242
Unauthenticated File Upload in Gogs
CVE-2026-25232
Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs
CVE-2026-25232
Gogs has a Protected Branch Deletion Bypass in Web Interface
CVE-2026-25120
Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs
CVE-2026-25120
Gogs Allows Cross-Repository Comment Deletion via DeleteComment
CVE-2026-25229
Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs
CVE-2026-25229
Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs
CVE-2025-65852
Gogs has authorization bypass in repository deletion API
GHSA-26gq-grmh-6xm6
Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs
Browse more Go advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes