Skip to content
RequestGuard Vulnerabilities
Pricing

gogs.io/gogs

Go package metadata, published advisories, affected versions, and known-exploitation evidence.

Go latest v0.13.3

Evidence path

Version, exploitation, severity

RequestGuard keeps these facts separate. A KEV match refers to a CVE, while OSV supplies the package and version match.

1

Latest version

v0.13.3

Published advisories match this version

2

Known exploitation

CISA KEV match

CVE-2025-8110

3

Highest advisory severity

Critical

76 active advisories

Check an exact version

The registry confirms the version, then OSV checks advisories for that exact value.

Published records

Advisories

76

Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion

Affected range

SEMVER: introduced 0; fixed 0.14.3SEMVER: introduced 0

Fixed versions: 0.14.3

Show 51 more advisories
GHSA-pwx3-qcgw-vh7h Gogs Vulnerable to CSRF Leading to Organization Owner Takeover
GHSA-w6j9-vw59-27wv Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers
GHSA-jq8v-rmf6-65jw Gogs has Stored XSS in `.ipynb` Preview
GHSA-pm6v-2h4w-4rp2 Gogs: Overwriting critical files results in a denial of service
GHSA-c4v7-xg93-qf8g Gogs has SSRF in webhook deliveries
GHSA-6vxv-wg6j-5qwp Gogs: XSS in .ipynb files renderer due to outdated notebookjs
GHSA-9hxg-w7qf-hh93 Gogs Directory Traversal
GHSA-v9vm-r24h-6rqm Gogs: Release tag option injection in release deletion
GHSA-xrcr-gmf5-2r8j Gogs: Stored XSS via data URI in issue comments
GHSA-vgjm-2cpf-4g7c Gogs: DOM-based XSS via milestone selection
GHSA-2c6v-8r3v-gh6p Gogs has a Protected Branch Deletion Bypass in Web Interface
GHSA-26gq-grmh-6xm6 Gogs vulnerable to Stored XSS via Mermaid diagrams
GHSA-p6x6-9mx6-26wj Gogs Vulnerable to 2FA Bypass via Recovery Code
GHSA-jp7c-wj6q-3qf2 Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update
GHSA-phm4-wf3h-pc3r Remote Code Execution in Gogs
GHSA-m27m-h5gj-wwmg Gogs allows argument Injection when tagging new releases
GHSA-g6xv-8q23-w2q3 SQL Injection in Gogs
GHSA-w689-557m-2cvq Server-Side Request Forgery in gogs webhook
GHSA-5gjh-5j4f-cpwv Unrestricted Upload of File with Dangerous Type in Gogs
GHSA-6vcc-v9vw-g2x5 Path Traversal in Git HTTP endpoints in Gogs
GHSA-gw5h-h6hj-f56g Gogs vulnerable to improper PAM authorization handling
GHSA-fg3x-rwq9-74cw Gogs and Gitea SSRF Vulnerability
GHSA-xh32-cx6c-cp4v Gogs XSS allowed by stored call in PDF renderer
GHSA-744x-3838-5r56 Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API
GHSA-vcm5-gvmp-78mp Gogs has DOM-based XSS via Milestone Name on New Issue Page
GHSA-xxhq-69mf-w8cr Gogs has an Open Redirect via redirect_to
GHSA-xp79-5mx3-jx52 Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion)
GHSA-3w28-36p9-w929 Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS
GHSA-4565-r4x7-hg8j Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation
GHSA-5c3f-6486-3g7g Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES
GHSA-3qq3-668m-v9mj Gogs has a Denial of Service in repository/wiki file listing web pages
GHSA-vgvf-m4fw-938j Gogs: Stored XSS in branch and wiki views through author and committer names
GHSA-x9p5-w45c-7ffc Gogs: Access tokens get exposed through URL params in API requests
GHSA-fc3h-92p8-h36f Unauthenticated File Upload in Gogs
GHSA-jj5m-h57j-5gv7 Gogs Allows Cross-Repository Comment Deletion via DeleteComment
GHSA-cv22-72px-f4gh Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs
GHSA-rjv5-9px2-fqw6 Gogs has authorization bypass in repository deletion API
GHSA-cr88-6mqm-4g57 Gogs has a Denial of Service issue
GHSA-mrph-w4hh-gx3g Gogs has arbitrary file read/write via Path Traversal in Git hook editing
GHSA-5qhx-gwfj-6jqr Gogs user can update repository content with read-only permission
GHSA-cpgw-2wxr-pww3 Open Redirect
GHSA-4c7m-vv47-7c69 Insecure Permissions in Gogs
GHSA-ff28-f46g-r9g8 Cross-site Scripting in Gogs
GHSA-9hx4-qm7h-x84j Cross-site Scripting in Gogs
GHSA-xq4v-vrp9-vcf2 Cross-site Scripting vulnerability in repository issue list in Gogs
GHSA-7v5r-r995-q2x2 SSRF in repository migration
GHSA-q347-cg56-pcq4 SSRF in repository migration
GHSA-px5r-fqj6-r2f8 Gogs XSS Vulnerability
GHSA-mr6h-chqp-p9g2 SQL Injection in gogs.io/gogs
GHSA-4j89-2c4f-44c6 Gogs has DoS in rendering issue index pattern
GHSA-pj96-4jhv-v792 Cross site scripting via cookies in gogs