Exposição de Gogs

Development
41
score de exposição
5
sites usam
1
em exploração
7
críticos
Análise Vexday

O Gogs, plataforma de hospedagem de repositórios Git, acumula 47 CVEs catalogadas, com 24 surgidas apenas nos últimos 90 dias — concentração recente que indica aumento significativo no escrutínio de segurança sobre o produto. A taxa de exploração ativa, com 1 CVE presente no catálogo KEV da CISA, situa-se 4,7 vezes acima da média geral do catálogo, o que merece atenção prioritária de equipes responsáveis por instâncias expostas. O CVE-2025-8110, a vulnerabilidade de maior risco ativo no momento, apresenta EPSS de 0,7654, indicando alta probabilidade de exploração em ambiente real. A falha mais recorrente é do tipo CWE-79 (Cross-Site Scripting), e o conjunto inclui 7 vulnerabilidades de severidade crítica, reforçando a necessidade de manter atualizações aplicadas e revisar controles de exposição da interface web.

CVEs

47 resultados
CVE-2025-8110HIGHFile overwrite in file update API in GogsEPSS 82.7%KEVCVE-2024-55947HIGHGogs has a Path Traversal in file update APIEPSS 75.2%CVE-2022-32174CRITICALGogs - XSSEPSS 58.0%CVE-2026-52806CRITICALGogs: RCE via git rebase --exec argument injection in pull request mergeEPSS 1.5%CVE-2025-64111CRITICALGogs's update .git/config file allows remote command executionEPSS 1.2%CVE-2026-52815MEDIUMGogs: Unauthenticated Organization Teams Information Disclosure via APIEPSS 1.1%CVE-2024-56731CRITICALGogs deletion of internal files allows remote command executionEPSS 0.9%CVE-2026-52813CRITICALGogs: Path Traversal in organization name results in RCE through Git hooksEPSS 0.9%CVE-2024-54148HIGHGogs has a Path Traversal in file editing UIEPSS 0.9%CVE-2022-31038MEDIUMXSS vulnerability in repository issue list in GogsEPSS 0.7%CVE-2026-24135HIGHGogs vulnerable to arbitrary file deletion via path traversal in wiki page updateEPSS 0.7%CVE-2026-25242MEDIUMGogs allows unauthenticated file uploadsEPSS 0.6%CVE-2026-25119HIGHGogs: Authentication Bypass via Unvalidated Reverse Proxy HeadersEPSS 0.6%CVE-2026-26194HIGHGogs: Release tag option injection in release deletionEPSS 0.5%CVE-2026-52816MEDIUMGogs: Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSSEPSS 0.5%CVE-2026-23633MEDIUMGogs has arbitrary file read/write via path traversal in Git hook editingEPSS 0.5%CVE-2026-52802MEDIUMGogs: Open Redirect via redirect_to in GogsEPSS 0.5%CVE-2026-52811CRITICALGogs: UploadRepoFiles writes outside repo working tree via committed parent symEPSS 0.5%CVE-2026-52797HIGHGogs: Overwriting critical files results in a denial of serviceEPSS 0.4%CVE-2026-25232HIGHGogs has a Protected Branch Deletion Bypass in Web InterfaceEPSS 0.4%