Exposição de Gogs

Development
39
score de exposição
3
sites usam
1
em exploração
7
críticos
Análise Vexday

O Gogs, plataforma de hospedagem de repositórios Git, acumula 47 CVEs catalogadas, com 24 surgidas apenas nos últimos 90 dias — concentração recente que indica aumento significativo no escrutínio de segurança sobre o produto. A taxa de exploração ativa, com 1 CVE presente no catálogo KEV da CISA, situa-se 4,7 vezes acima da média geral do catálogo, o que merece atenção prioritária de equipes responsáveis por instâncias expostas. O CVE-2025-8110, a vulnerabilidade de maior risco ativo no momento, apresenta EPSS de 0,7654, indicando alta probabilidade de exploração em ambiente real. A falha mais recorrente é do tipo CWE-79 (Cross-Site Scripting), e o conjunto inclui 7 vulnerabilidades de severidade crítica, reforçando a necessidade de manter atualizações aplicadas e revisar controles de exposição da interface web.

CVEs

47 resultados
CVE-2025-8110HIGHFile overwrite in file update API in GogsEPSS 82.5%KEVCVE-2024-55947HIGHGogs has a Path Traversal in file update APIEPSS 75.2%CVE-2022-32174CRITICALGogs - XSSEPSS 58.0%CVE-2026-52806CRITICALGogs: RCE via git rebase --exec argument injection in pull request mergeEPSS 7.9%CVE-2026-52815MEDIUMGogs: Unauthenticated Organization Teams Information Disclosure via APIEPSS 1.5%CVE-2025-64111CRITICALGogs's update .git/config file allows remote command executionEPSS 1.3%CVE-2026-52813CRITICALGogs: Path Traversal in organization name results in RCE through Git hooksEPSS 1.1%CVE-2024-56731CRITICALGogs deletion of internal files allows remote command executionEPSS 1.1%CVE-2026-25119HIGHGogs: Authentication Bypass via Unvalidated Reverse Proxy HeadersEPSS 0.9%CVE-2024-54148HIGHGogs has a Path Traversal in file editing UIEPSS 0.9%CVE-2022-31038MEDIUMXSS vulnerability in repository issue list in GogsEPSS 0.7%CVE-2026-24135HIGHGogs vulnerable to arbitrary file deletion via path traversal in wiki page updateEPSS 0.7%CVE-2026-52816MEDIUMGogs: Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSSEPSS 0.7%CVE-2026-25242MEDIUMGogs allows unauthenticated file uploadsEPSS 0.6%CVE-2026-52801HIGHGogs: Ability to import local repositories via Mirror SettingsEPSS 0.6%CVE-2026-52802MEDIUMGogs: Open Redirect via redirect_to in GogsEPSS 0.6%CVE-2026-52814MEDIUMGogs: Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion)EPSS 0.5%CVE-2026-52797HIGHGogs: Overwriting critical files results in a denial of serviceEPSS 0.5%CVE-2026-26194HIGHGogs: Release tag option injection in release deletionEPSS 0.5%CVE-2026-52804MEDIUMGogs: Privilege Escalation via Collaboration Access Mode ValidationEPSS 0.5%