CVE-2026-52805

HIGH

Gogs: Migration Redirect Bypass Leads to Internal Repository Theft

Title source: cna
STIX 2.1

Description

Gogs is an open source self-hosted Git service. Prior to 0.14.3, a Server-Side Request Forgery (SSRF) vulnerability exists in the repository migration functionality. The application validates only the initially submitted URL hostname, but git clone --mirror follows HTTP redirects. An authenticated user can submit a public URL that redirects to a blocked internal endpoint (e.g., 127.0.0.1), importing the internal repository's contents into an attacker-controlled repository. This vulnerability is fixed in 0.14.3.

References (4)

Core 4

Scores

CVSS v3 8.7
EPSS 0.0028
EPSS Percentile 20.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-918
Status published
Products (2)
gogs/gogs < 0.14.3
gogs.io/gogs 0 - 0.14.3Go
Published Jun 24, 2026
Tracked Since Jun 25, 2026