CVE-2026-52805

Published
View on NVD ↗
CVSS v3
8.7
HIGH
CVSS v2
N/A
Affected
1
PROJECT

Description

Gogs is an open source self-hosted Git service. Prior to 0.14.3, a Server-Side Request Forgery (SSRF) vulnerability exists in the repository migration functionality. The application validates only the initially submitted URL hostname, but git clone --mirror follows HTTP redirects. An authenticated user can submit a public URL that redirects to a blocked internal endpoint (e.g., 127.0.0.1), importing the internal repository's contents into an attacker-controlled repository. This vulnerability is fixed in 0.14.3.

The painless way to host your own Git service
GitHubGitHub
47.6K