go

gogs.io/gogs

View on go registry
100 Total advisories
100 Vulnerabilities
0 Malware

Dependency scanning

Check whether gogs.io/gogs is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

HIGH 8.8
Go

CVE-2026-52800

Gogs Vulnerable to CSRF Leading to Organization Owner Takeover

UNKNOWN
Go

CVE-2021-32546

OS Command Injection in gogs

UNKNOWN
Go

CVE-2026-25119

Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers

HIGH 8.1
Go

CVE-2026-52801

Gogs has the ability to import local repositories via Mirror Settings

HIGH 7.1
Go

CVE-2026-52808

Gogs's write-level collaborators can mutate admin-only repository settings via API

UNKNOWN
Go

CVE-2026-52810

Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion

UNKNOWN
Go

CVE-2026-52807

Gogs has DOM-based XSS via Milestone Name on New Issue Page

CRITICAL 9.9
Go

CVE-2026-52806

Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge

MEDIUM 5.4
Go

CVE-2026-52802

Gogs has an Open Redirect via redirect_to

HIGH 8.9
Go

CVE-2026-52798

Gogs has Stored XSS in `.ipynb` Preview

HIGH 7.5
Go

CVE-2026-52799

Gogs Missing Authorization in Attachment Download

UNKNOWN
Go

CVE-2026-52814

Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion)

HIGH 8.5
Go

CVE-2026-52797

Gogs: Overwriting critical files results in a denial of service

UNKNOWN
Go

CVE-2026-52814

Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs

UNKNOWN
Go

CVE-2026-52806

Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs

UNKNOWN
Go

CVE-2026-52800

Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs

UNKNOWN
Go

CVE-2026-52801

Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs

UNKNOWN
Go

CVE-2026-52810

Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs

UNKNOWN
Go

CVE-2026-25119

Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs

UNKNOWN
Go

CVE-2026-52807

Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs

UNKNOWN
Go

CVE-2026-52797

Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs

UNKNOWN
Go

CVE-2026-52799

Gogs Missing Authorization in Attachment Download in gogs.io/gogs

UNKNOWN
Go

CVE-2026-52798

Gogs has Stored XSS in `.ipynb` Preview in gogs.io/gogs

UNKNOWN
Go

CVE-2026-52802

Gogs has an Open Redirect via redirect_to in gogs.io/gogs

UNKNOWN
Go

CVE-2026-52808

Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs

UNKNOWN
Go

GO-2026-5193

Gogs: XSS in .ipynb files renderer due to outdated notebookjs

HIGH 8.7
Go

CVE-2026-52805

Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft

UNKNOWN
Go

CVE-2026-47267

Gogs has SSRF in webhook deliveries

UNKNOWN
Go

CVE-2026-52815

Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API

CRITICAL 10.0
Go

CVE-2026-52813

Gogs has Path Traversal in organization name that results in RCE through Git hooks

UNKNOWN
Go

CVE-2026-52812

Gogs: LFS dedupe path leaks private repo content across tenants

UNKNOWN
Go

CVE-2026-52811

Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym

UNKNOWN
Go

CVE-2026-52805

Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs

UNKNOWN
Go

CVE-2026-52813

Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs

UNKNOWN
Go

CVE-2026-52811

Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs

UNKNOWN
Go

CVE-2026-47267

Gogs has SSRF in webhook deliveries in gogs.io/gogs

UNKNOWN
Go

CVE-2026-52815

Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs

UNKNOWN
Go

GHSA-6vxv-wg6j-5qwp

Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs

UNKNOWN
Go

CVE-2026-52812

Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs

LOW 3.5
Go

CVE-2026-52796

Gogs has DoS in rendering issue index pattern

MEDIUM 6.8
Go

CVE-2026-52809

Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES

MEDIUM 4.9
Go

CVE-2025-64719

Gogs has a Denial of Service in repository/wiki file listing web pages

UNKNOWN
Go

CVE-2026-52804

Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation

UNKNOWN
Go

CVE-2026-52816

Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS

UNKNOWN
Go

CVE-2026-52809

Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs

UNKNOWN
Go

CVE-2026-52796

Gogs has DoS in rendering issue index pattern in gogs.io/gogs

UNKNOWN
Go

CVE-2026-52816

Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs

UNKNOWN
Go

CVE-2026-52804

Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs

UNKNOWN
Go

CVE-2025-64719

Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs

HIGH 7.5
Go

CVE-2018-20303

Gogs Directory Traversal

UNKNOWN
Go

CVE-2026-26194

Gogs: Release tag option injection in release deletion

HIGH 8.7
Go

CVE-2026-26022

Gogs: Stored XSS via data URI in issue comments

CRITICAL 9.3
Go

CVE-2026-25921

Gogs: Cross-repository LFS object overwrite via missing content hash verification

HIGH 7.3
Go

CVE-2026-26276

Gogs: DOM-based XSS via milestone selection

UNKNOWN
Go

CVE-2026-26195

Gogs: Stored XSS in branch and wiki views through author and committer names

MEDIUM 5.3
Go

CVE-2026-26196

Gogs: Access tokens get exposed through URL params in API requests

UNKNOWN
Go

CVE-2026-26276

Gogs: DOM-based XSS via milestone selection in gogs.io/gogs

UNKNOWN
Go

CVE-2026-26022

Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs

UNKNOWN
Go

CVE-2026-26195

Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs

UNKNOWN
Go

CVE-2026-26194

Gogs: Release tag option injection in release deletion in gogs.io/gogs

UNKNOWN
Go

CVE-2026-25921

Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs

UNKNOWN
Go

CVE-2026-26196

Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs

UNKNOWN
Go KEV

CVE-2025-8110

Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs

UNKNOWN
Go

CVE-2024-56731

Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs

UNKNOWN
Go

CVE-2025-47943

Gogs XSS allowed by stored call in PDF renderer in gogs.io/gogs

UNKNOWN
Go

CVE-2024-54148

Remote Command Execution in file editing in gogs in gogs.io/gogs

UNKNOWN
Go

CVE-2024-55947

Path Traversal in file update API in gogs in gogs.io/gogs

UNKNOWN
Go

CVE-2024-44625

Unpatched Remote Code Execution in Gogs in gogs.io/gogs

UNKNOWN
Go

CVE-2018-15192

Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea

UNKNOWN
Go

CVE-2018-17031

Gogs XSS Vulnerability in gogs.io/gogs

UNKNOWN
Go

CVE-2022-2024

Gogs OS Command Injection vulnerability in gogs.io/gogs

UNKNOWN
Go

CVE-2022-32174

Gogs vulnerable to Cross-site Scripting in gogs.io/gogs

UNKNOWN
Go

CVE-2014-8682

SQL Injection in Gogs in gogs.io/gogs

UNKNOWN
Go

CVE-2019-14544

Insecure Permissions in Gogs in gogs.io/gogs

UNKNOWN
Go

GHSA-q347-cg56-pcq4

SSRF in repository migration in gogs.io/gogs

UNKNOWN
Go

CVE-2018-15178

Open Redirect in gogs.io/gogs

UNKNOWN
Go

CVE-2020-14958

Insecure Permissions in Gogs in gogs.io/gogs

UNKNOWN
Go

CVE-2022-1884

OS Command Injection in gogs in gogs.io/gogs

UNKNOWN
Go

CVE-2014-8683

Cross-site Scripting in Gogs in gogs.io/gogs

UNKNOWN
Go

CVE-2022-1464

Cross-site Scripting in Gogs in gogs.io/gogs

UNKNOWN
Go

CVE-2022-0870

SSRF in repository migration in gogs.io/gogs

UNKNOWN
Go

CVE-2022-1285

Server-Side Request Forgery in gogs webhook in gogs.io/gogs

UNKNOWN
Go

CVE-2022-1992

Path Traversal in file editor on Windows in Gogs in gogs.io/gogs

UNKNOWN
Go

CVE-2022-1993

Path Traversal in Git HTTP endpoints in Gogs in gogs.io/gogs

UNKNOWN
Go

CVE-2022-1986

OS Command Injection in file editor in Gogs in gogs.io/gogs

UNKNOWN
Go

CVE-2022-0415

Unrestricted Upload of File with Dangerous Type in Gogs in gogs.io/gogs

UNKNOWN
Go

CVE-2022-31038

Cross-site Scripting vulnerability in repository issue list in Gogs in gogs.io/gogs

UNKNOWN
Go

CVE-2021-32546

OS Command Injection in gogs in gogs.io/gogs

UNKNOWN
Go

GHSA-pj96-4jhv-v792

Cross site scripting via cookies in gogs in gogs.io/gogs

UNKNOWN
Go

CVE-2022-0871

Gogs vulnerable to improper PAM authorization handling in gogs.io/gogs

UNKNOWN
Go

CVE-2026-25242

Unauthenticated File Upload in Gogs in gogs.io/gogs

UNKNOWN
Go

CVE-2026-25242

Unauthenticated File Upload in Gogs

UNKNOWN
Go

CVE-2026-25232

Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs

UNKNOWN
Go

CVE-2026-25232

Gogs has a Protected Branch Deletion Bypass in Web Interface

UNKNOWN
Go

CVE-2026-25120

Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs

UNKNOWN
Go

CVE-2026-25120

Gogs Allows Cross-Repository Comment Deletion via DeleteComment

UNKNOWN
Go

CVE-2026-25229

Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs

UNKNOWN
Go

CVE-2026-25229

Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs

UNKNOWN
Go

CVE-2025-65852

Gogs has authorization bypass in repository deletion API

UNKNOWN
Go

GHSA-26gq-grmh-6xm6

Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes