Vulnerabilidades en Gogs
57 resultadosAnálisis Vexday
Gogs apresenta 1 vulnerabilidade catalogada, integralmente sob exploração ativa (KEV), relacionada a traversal de diretório (CWE-22). Embora nenhuma seja crítica por CVSS e sem publicações recentes, a exploração em campo representa risco imediato para ambientes em produção.
CVE-2026-24135HIGHGogs vulnerable to arbitrary file deletion via path traversal in wiki page updateEPSS 0.7%CVE-2026-25242MEDIUMGogs allows unauthenticated file uploadsEPSS 0.6%CVE-2026-25119HIGHGogs: Authentication Bypass via Unvalidated Reverse Proxy HeadersEPSS 0.6%CVE-2026-26194HIGHGogs: Release tag option injection in release deletionEPSS 0.5%CVE-2026-52816MEDIUMGogs: Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSSEPSS 0.5%CVE-2026-52802MEDIUMGogs: Open Redirect via redirect_to in GogsEPSS 0.5%CVE-2026-23633MEDIUMGogs has arbitrary file read/write via path traversal in Git hook editingEPSS 0.5%CVE-2026-52811CRITICALGogs: UploadRepoFiles writes outside repo working tree via committed parent symEPSS 0.5%CVE-2026-52797HIGHGogs: Overwriting critical files results in a denial of serviceEPSS 0.4%CVE-2026-25232HIGHGogs has a Protected Branch Deletion Bypass in Web InterfaceEPSS 0.4%CVE-2026-52814MEDIUMGogs: Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion)EPSS 0.4%CVE-2025-64175HIGHGogs Vulnerable to 2FA Bypass via Recovery CodeEPSS 0.4%CVE-2026-52801HIGHGogs: Ability to import local repositories via Mirror SettingsEPSS 0.4%CVE-2026-52799HIGHGogs: Missing Authorization in Attachment DownloadEPSS 0.4%CVE-2026-52807MEDIUMGogs: DOM-based XSS via Milestone Name on New Issue PageEPSS 0.4%CVE-2026-52804MEDIUMGogs: Privilege Escalation via Collaboration Access Mode ValidationEPSS 0.4%CVE-2025-64719MEDIUMGogs: Denial of Service in repository/wiki file listing web pagesEPSS 0.3%CVE-2026-52810HIGHGogs: Write to readonly repositories using receive-pack + service=git-upload-pack confusionEPSS 0.3%CVE-2026-22592MEDIUMGogs is Vulnerable to Denial of ServiceEPSS 0.3%CVE-2026-52808HIGHGogs: Write-level collaborators can mutate admin-only repository settings via APIEPSS 0.3%