{"schema_version":1,"title":"Gogs vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 27 vulnerabilities in Gogs: 0 in the last 7 days and 0 in the last 90 days, 4 of them critical and 1 exploited in the wild. The most recent, CVE-2026-52816, was published on 24 June 2026.","url":"https://junglewise.ai/threats/technologies/gogs","json_url":"https://junglewise.ai/threats/technologies/gogs.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/gogs","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":14,"all_time":27,"critical":4,"exploited":1,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":26},"latest":[{"cve":"CVE-2026-52816","cvss":4,"epss":0.0068,"slug":"cve-2026-52816-gogs-stored-xss-in-jupyter-notebook-sanitizer-endpoint","title":"Gogs stored XSS in Jupyter Notebook sanitizer endpoint","severity":"medium","exploited":false,"published_at":"2026-06-24T21:16:57.753+00:00","url":"https://junglewise.ai/threats/cve-2026-52816-gogs-stored-xss-in-jupyter-notebook-sanitizer-endpoint"},{"cve":"CVE-2026-52815","cvss":4,"epss":0.0149,"slug":"cve-2026-52815-gogs-unauthenticated-information-disclosure-in-organization-teams","title":"Gogs unauthenticated information disclosure in organization teams API","severity":"medium","exploited":false,"published_at":"2026-06-24T21:16:57.627+00:00","url":"https://junglewise.ai/threats/cve-2026-52815-gogs-unauthenticated-information-disclosure-in-organization-teams"},{"cve":"CVE-2026-52814","cvss":4,"epss":0.0055,"slug":"cve-2026-52814-gogs-denial-of-service-via-ssh-handshake-stall-in-built-in-ssh","title":"Gogs Denial of Service via SSH handshake stall in built-in SSH server","severity":"medium","exploited":false,"published_at":"2026-06-24T21:16:57.497+00:00","url":"https://junglewise.ai/threats/cve-2026-52814-gogs-denial-of-service-via-ssh-handshake-stall-in-built-in-ssh"},{"cve":"CVE-2026-52813","cvss":10,"epss":0.0111,"slug":"cve-2026-52813-gogs-path-traversal-and-rce-via-organization-names","title":"Gogs path traversal and RCE via organization names","severity":"critical","exploited":false,"published_at":"2026-06-24T21:16:57.353+00:00","url":"https://junglewise.ai/threats/cve-2026-52813-gogs-path-traversal-and-rce-via-organization-names"},{"cve":"CVE-2026-52812","cvss":4,"epss":0.0024,"slug":"cve-2026-52812-gogs-git-lfs-cross-repository-disclosure-via-insufficient-oid","title":"Gogs Git LFS cross-repository disclosure via insufficient OID verification","severity":"high","exploited":false,"published_at":"2026-06-24T21:16:57.223+00:00","url":"https://junglewise.ai/threats/cve-2026-52812-gogs-git-lfs-cross-repository-disclosure-via-insufficient-oid"},{"cve":"CVE-2026-52811","cvss":4,"epss":0.0047,"slug":"cve-2026-52811-gogs-arbitrary-file-write-via-symlink-following-in","title":"Gogs arbitrary file write via symlink following in UploadRepoFiles","severity":"critical","exploited":false,"published_at":"2026-06-24T21:16:57.093+00:00","url":"https://junglewise.ai/threats/cve-2026-52811-gogs-arbitrary-file-write-via-symlink-following-in"},{"cve":"CVE-2026-52810","cvss":4,"epss":0.0043,"slug":"cve-2026-52810-gogs-improper-access-control-in-git-smart-http-push-authorization","title":"Gogs improper access control in Git smart HTTP push authorization","severity":"high","exploited":false,"published_at":"2026-06-24T21:16:56.96+00:00","url":"https://junglewise.ai/threats/cve-2026-52810-gogs-improper-access-control-in-git-smart-http-push-authorization"},{"cve":"CVE-2026-52809","cvss":6.8,"epss":0.002,"slug":"cve-2026-52809-gogs-insufficient-session-expiration-in-password-reset-tokens","title":"Gogs insufficient session expiration in password reset tokens","severity":"medium","exploited":false,"published_at":"2026-06-24T21:16:56.827+00:00","url":"https://junglewise.ai/threats/cve-2026-52809-gogs-insufficient-session-expiration-in-password-reset-tokens"},{"cve":"CVE-2026-52808","cvss":7.1,"epss":0.0048,"slug":"cve-2026-52808-gogs-incorrect-authorization-in-repository-settings-api","title":"Gogs incorrect authorization in repository settings API","severity":"high","exploited":false,"published_at":"2026-06-24T21:16:56.693+00:00","url":"https://junglewise.ai/threats/cve-2026-52808-gogs-incorrect-authorization-in-repository-settings-api"},{"cve":"CVE-2026-52807","cvss":4,"epss":0.0048,"slug":"cve-2026-52807-gogs-stored-dom-based-xss-in-milestone-dropdown-on-new-issue-page","title":"Gogs stored DOM-based XSS in milestone dropdown on New Issue page","severity":"high","exploited":false,"published_at":"2026-06-24T21:16:56.57+00:00","url":"https://junglewise.ai/threats/cve-2026-52807-gogs-stored-dom-based-xss-in-milestone-dropdown-on-new-issue-page"},{"cve":"CVE-2026-52806","cvss":9.9,"epss":0.0793,"slug":"cve-2026-52806-gogs-remote-code-execution-via-git-rebase-argument-injection","title":"Gogs Remote Code Execution via git rebase argument injection","severity":"critical","exploited":false,"published_at":"2026-06-24T21:16:56.44+00:00","url":"https://junglewise.ai/threats/cve-2026-52806-gogs-remote-code-execution-via-git-rebase-argument-injection"},{"cve":"CVE-2026-52805","cvss":8.7,"epss":0.0038,"slug":"cve-2026-52805-gogs-ssrf-in-repository-migration-and-mirror-sync","title":"Gogs SSRF in repository migration and mirror sync","severity":"high","exploited":false,"published_at":"2026-06-24T21:16:56.317+00:00","url":"https://junglewise.ai/threats/cve-2026-52805-gogs-ssrf-in-repository-migration-and-mirror-sync"},{"cve":"CVE-2026-52804","cvss":4,"epss":0.005,"slug":"cve-2026-52804-gogs-privilege-escalation-in-changecollaborationaccessmode","title":"Gogs privilege escalation in ChangeCollaborationAccessMode","severity":"medium","exploited":false,"published_at":"2026-06-24T21:16:56.187+00:00","url":"https://junglewise.ai/threats/cve-2026-52804-gogs-privilege-escalation-in-changecollaborationaccessmode"},{"cve":"CVE-2026-52802","cvss":5.4,"epss":0.0055,"slug":"cve-2026-52802-gogs-open-redirect-in-issamesite-validation","title":"Gogs open redirect in IsSameSite validation","severity":"medium","exploited":false,"published_at":"2026-06-24T21:16:56.057+00:00","url":"https://junglewise.ai/threats/cve-2026-52802-gogs-open-redirect-in-issamesite-validation"},{"cve":"CVE-2026-52801","cvss":8.1,"epss":0.0057,"slug":"cve-2026-52801-gogs-ssrf-and-local-file-disclosure-in-mirror-settings","title":"Gogs SSRF and local file disclosure in Mirror Settings","severity":"high","exploited":false,"published_at":"2026-06-24T21:16:55.93+00:00","url":"https://junglewise.ai/threats/cve-2026-52801-gogs-ssrf-and-local-file-disclosure-in-mirror-settings"},{"cve":"CVE-2026-52800","cvss":8.8,"epss":0.0025,"slug":"cve-2026-52800-gogs-csrf-in-organization-team-management","title":"Gogs CSRF in organization team management","severity":"high","exploited":false,"published_at":"2026-06-24T21:16:55.8+00:00","url":"https://junglewise.ai/threats/cve-2026-52800-gogs-csrf-in-organization-team-management"},{"cve":"CVE-2026-52799","cvss":7.5,"epss":0.0042,"slug":"cve-2026-52799-gogs-missing-authorization-in-attachment-download-endpoint","title":"Gogs missing authorization in attachment download endpoint","severity":"high","exploited":false,"published_at":"2026-06-24T21:16:55.67+00:00","url":"https://junglewise.ai/threats/cve-2026-52799-gogs-missing-authorization-in-attachment-download-endpoint"},{"cve":"CVE-2026-52798","cvss":8.9,"epss":0.0043,"slug":"cve-2026-52798-gogs-stored-xss-in-jupyter-notebook-preview","title":"Gogs stored XSS in Jupyter notebook preview","severity":"high","exploited":false,"published_at":"2026-06-24T21:16:55.533+00:00","url":"https://junglewise.ai/threats/cve-2026-52798-gogs-stored-xss-in-jupyter-notebook-preview"},{"cve":"CVE-2026-52797","cvss":8.5,"epss":0.0053,"slug":"cve-2026-52797-gogs-path-traversal-and-argument-injection-in-git-diff-preview","title":"Gogs path traversal and argument injection in git diff preview","severity":"high","exploited":false,"published_at":"2026-06-24T21:16:55.403+00:00","url":"https://junglewise.ai/threats/cve-2026-52797-gogs-path-traversal-and-argument-injection-in-git-diff-preview"},{"cve":"CVE-2026-52796","cvss":3.5,"epss":0.0028,"slug":"cve-2026-52796-gogs-denial-of-service-via-malformed-issue-index-pattern","title":"Gogs denial of service via malformed issue index pattern","severity":"low","exploited":false,"published_at":"2026-06-24T21:16:55.27+00:00","url":"https://junglewise.ai/threats/cve-2026-52796-gogs-denial-of-service-via-malformed-issue-index-pattern"},{"cve":"CVE-2026-52795","cvss":4.3,"slug":"cve-2026-52795-gogs-incorrect-authorization-in-watch-api","title":"Gogs incorrect authorization in Watch API","severity":"medium","exploited":false,"published_at":"2026-06-24T21:16:55.143+00:00","url":"https://junglewise.ai/threats/cve-2026-52795-gogs-incorrect-authorization-in-watch-api"},{"cve":"CVE-2026-47267","cvss":8.3,"epss":0.0042,"slug":"cve-2026-47267-gogs-ssrf-via-webhook-redirect-bypass","title":"Gogs SSRF via webhook redirect bypass","severity":"high","exploited":false,"published_at":"2026-06-24T21:16:54.347+00:00","url":"https://junglewise.ai/threats/cve-2026-47267-gogs-ssrf-via-webhook-redirect-bypass"},{"cve":"CVE-2026-25119","cvss":4,"epss":0.0086,"slug":"cve-2026-25119-gogs-authentication-bypass-via-spoofed-reverse-proxy-headers","title":"Gogs authentication bypass via spoofed reverse proxy headers","severity":"high","exploited":false,"published_at":"2026-06-24T21:16:52.903+00:00","url":"https://junglewise.ai/threats/cve-2026-25119-gogs-authentication-bypass-via-spoofed-reverse-proxy-headers"},{"cve":"CVE-2025-64719","cvss":4.9,"epss":0.0044,"slug":"cve-2025-64719-gogs-denial-of-service-via-malformed-filenames-in-repository-or","title":"Gogs denial of service via malformed filenames in repository or wiki","severity":"medium","exploited":false,"published_at":"2026-06-24T21:16:52.007+00:00","url":"https://junglewise.ai/threats/cve-2025-64719-gogs-denial-of-service-via-malformed-filenames-in-repository-or"},{"cvss":8.5,"slug":"gogs-xss-in-jupyter-notebook-renderer-via-outdated-notebookjs-07feca4b","title":"Gogs XSS in Jupyter notebook renderer via outdated notebookjs","severity":"high","exploited":false,"published_at":"2026-06-19T21:42:52+00:00","url":"https://junglewise.ai/threats/gogs-xss-in-jupyter-notebook-renderer-via-outdated-notebookjs-07feca4b"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"Gogs","slug":"gogs","vendor":{"name":"Gogs","slug":"gogs","url":"https://junglewise.ai/threats/vendors/gogs"},"aliases":[],"category":"git-service","homepage":"https://gogs.io/","repo_url":"https://github.com/gogs/gogs","description":"Gogs is a painless self-hosted Git service written in the Go programming language.","url":"https://junglewise.ai/threats/technologies/gogs"},"most_severe":[{"cve":"CVE-2025-8110","cvss":4,"epss":0.852,"slug":"cve-2025-8110-gogs-path-traversal-and-code-execution-in-putcontents-api","title":"GO-2025-4225 - Gogs vulnerable to a bypass of in gogs.io/gogs","severity":"critical","exploited":true,"published_at":"2025-12-15T20:15:46+00:00","url":"https://junglewise.ai/threats/cve-2025-8110-gogs-path-traversal-and-code-execution-in-putcontents-api"},{"cve":"CVE-2026-52813","cvss":10,"epss":0.0111,"slug":"cve-2026-52813-gogs-path-traversal-and-rce-via-organization-names","title":"Gogs path traversal and RCE via organization names","severity":"critical","exploited":false,"published_at":"2026-06-24T21:16:57.353+00:00","url":"https://junglewise.ai/threats/cve-2026-52813-gogs-path-traversal-and-rce-via-organization-names"},{"cve":"CVE-2026-52806","cvss":9.9,"epss":0.0793,"slug":"cve-2026-52806-gogs-remote-code-execution-via-git-rebase-argument-injection","title":"Gogs Remote Code Execution via git rebase argument injection","severity":"critical","exploited":false,"published_at":"2026-06-24T21:16:56.44+00:00","url":"https://junglewise.ai/threats/cve-2026-52806-gogs-remote-code-execution-via-git-rebase-argument-injection"},{"cve":"CVE-2026-52811","cvss":4,"epss":0.0047,"slug":"cve-2026-52811-gogs-arbitrary-file-write-via-symlink-following-in","title":"Gogs arbitrary file write via symlink following in UploadRepoFiles","severity":"critical","exploited":false,"published_at":"2026-06-24T21:16:57.093+00:00","url":"https://junglewise.ai/threats/cve-2026-52811-gogs-arbitrary-file-write-via-symlink-following-in"},{"cve":"CVE-2026-52798","cvss":8.9,"epss":0.0043,"slug":"cve-2026-52798-gogs-stored-xss-in-jupyter-notebook-preview","title":"Gogs stored XSS in Jupyter notebook preview","severity":"high","exploited":false,"published_at":"2026-06-24T21:16:55.533+00:00","url":"https://junglewise.ai/threats/cve-2026-52798-gogs-stored-xss-in-jupyter-notebook-preview"},{"cve":"CVE-2026-52800","cvss":8.8,"epss":0.0025,"slug":"cve-2026-52800-gogs-csrf-in-organization-team-management","title":"Gogs CSRF in organization team management","severity":"high","exploited":false,"published_at":"2026-06-24T21:16:55.8+00:00","url":"https://junglewise.ai/threats/cve-2026-52800-gogs-csrf-in-organization-team-management"},{"cve":"CVE-2026-52805","cvss":8.7,"epss":0.0038,"slug":"cve-2026-52805-gogs-ssrf-in-repository-migration-and-mirror-sync","title":"Gogs SSRF in repository migration and mirror sync","severity":"high","exploited":false,"published_at":"2026-06-24T21:16:56.317+00:00","url":"https://junglewise.ai/threats/cve-2026-52805-gogs-ssrf-in-repository-migration-and-mirror-sync"},{"cve":"CVE-2026-52797","cvss":8.5,"epss":0.0053,"slug":"cve-2026-52797-gogs-path-traversal-and-argument-injection-in-git-diff-preview","title":"Gogs path traversal and argument injection in git diff preview","severity":"high","exploited":false,"published_at":"2026-06-24T21:16:55.403+00:00","url":"https://junglewise.ai/threats/cve-2026-52797-gogs-path-traversal-and-argument-injection-in-git-diff-preview"},{"cvss":8.5,"slug":"gogs-xss-in-jupyter-notebook-renderer-via-outdated-notebookjs-07feca4b","title":"Gogs XSS in Jupyter notebook renderer via outdated notebookjs","severity":"high","exploited":false,"published_at":"2026-06-19T21:42:52+00:00","url":"https://junglewise.ai/threats/gogs-xss-in-jupyter-notebook-renderer-via-outdated-notebookjs-07feca4b"},{"cve":"CVE-2026-47267","cvss":8.3,"epss":0.0042,"slug":"cve-2026-47267-gogs-ssrf-via-webhook-redirect-bypass","title":"Gogs SSRF via webhook redirect bypass","severity":"high","exploited":false,"published_at":"2026-06-24T21:16:54.347+00:00","url":"https://junglewise.ai/threats/cve-2026-47267-gogs-ssrf-via-webhook-redirect-bypass"}],"generated_at":"2026-09-26T16:07:00.132667+00:00"}