CVE-2026-47267

Published
View on NVD ↗
CVSS v3
8.3
HIGH
CVSS v2
N/A
Affected
1
PROJECT

Description

Gogs is an open source self-hosted Git service. Prior to 0.14.3, the fix for CVE-2022-1285 prevents adding webooks or running webhooks with URLs with a hostname that resolves in localCIDRs. However, webhooks still follow redirects allowing to access hostname inside localCIDRs. This vulnerability is fixed in 0.14.3.

The painless way to host your own Git service
GitHubGitHub
47.6K