Vulnerabilidades en gogs

57 resultados
Análisis Vexday

O Gogs acumula 56 CVEs catalogadas, com 12 classificadas como críticas e 24 surgidas apenas nos últimos 90 dias, o que indica um ritmo recente de descobertas que merece atenção contínua. Embora nenhuma CVE esteja confirmada no catálogo CISA KEV — taxa abaixo da média geral do catálogo —, o CVE-2022-2024 apresenta EPSS de 0.9784, sinalizando altíssima probabilidade de exploração segundo os modelos preditivos, o que representa risco concreto independentemente da ausência de registro KEV. O tipo de falha mais comum é CWE-79 (Cross-Site Scripting), padrão recorrente em plataformas de hospedagem de código que expõe usuários a ataques de injeção de conteúdo. Equipes que operam instâncias autossuficientes do Gogs devem priorizar a remediação das vulnerabilidades críticas e monitorar ativamente o CVE-2022-2024 dado seu perfil de risco elevado.

CVE-2022-2024CRITICALOS Command Injection in gogs/gogsEPSS 97.8%CVE-2025-8110HIGHFile overwrite in file update API in GogsEPSS 85.2%KEVCVE-2024-55947HIGHGogs has a Path Traversal in file update APIEPSS 75.2%CVE-2022-0415CRITICALRemote Command Execution in uploading repository file in gogs/gogsEPSS 65.2%CVE-2022-32174CRITICALGogs - XSSEPSS 58.0%CVE-2022-1993HIGHPath Traversal in gogs/gogsEPSS 36.3%CVE-2026-52806CRITICALGogs: RCE via git rebase --exec argument injection in pull request mergeEPSS 7.9%CVE-2022-1986CRITICALOS Command Injection in gogs/gogsEPSS 4.5%CVE-2022-0870MEDIUMServer-Side Request Forgery (SSRF) in gogs/gogsEPSS 3.4%CVE-2022-1992CRITICALPath Traversal in gogs/gogsEPSS 2.3%CVE-2022-1884CRITICALRemote Command Execution in gogs/gogsEPSS 1.8%CVE-2026-52815MEDIUMGogs: Unauthenticated Organization Teams Information Disclosure via APIEPSS 1.5%CVE-2025-64111CRITICALGogs's update .git/config file allows remote command executionEPSS 1.3%CVE-2022-0871HIGHMissing Authorization in gogs/gogsEPSS 1.2%CVE-2026-52813CRITICALGogs: Path Traversal in organization name results in RCE through Git hooksEPSS 1.1%CVE-2022-1285HIGHServer-Side Request Forgery (SSRF) in gogs/gogsEPSS 1.1%CVE-2024-56731CRITICALGogs deletion of internal files allows remote command executionEPSS 1.1%CVE-2026-24135HIGHGogs vulnerable to arbitrary file deletion via path traversal in wiki page updateEPSS 0.9%CVE-2026-25119HIGHGogs: Authentication Bypass via Unvalidated Reverse Proxy HeadersEPSS 0.9%CVE-2024-54148HIGHGogs has a Path Traversal in file editing UIEPSS 0.9%