CVE-2026-52805
HIGHGogs: Migration Redirect Bypass Leads to Internal Repository Theft
Title source: cnaDescription
Gogs is an open source self-hosted Git service. Prior to 0.14.3, a Server-Side Request Forgery (SSRF) vulnerability exists in the repository migration functionality. The application validates only the initially submitted URL hostname, but git clone --mirror follows HTTP redirects. An authenticated user can submit a public URL that redirects to a blocked internal endpoint (e.g., 127.0.0.1), importing the internal repository's contents into an attacker-controlled repository. This vulnerability is fixed in 0.14.3.
References (4)
Core 4
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/gogs/gogs/security/advisories/GHSA-g2f5-gjr4-qjvm
X_Refsource_Misc x_refsource_misc
https://github.com/gogs/gogs/pull/8324
X_Refsource_Misc x_refsource_misc
https://github.com/gogs/gogs/commit/b9a0093e9cd1b2b3c7f42f9feca396dc772c4f1b
X_Refsource_Misc x_refsource_misc
https://github.com/gogs/gogs/releases/tag/v0.14.3
Scores
CVSS v3
8.7
EPSS
0.0028
EPSS Percentile
20.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-918
Status
published
Products (2)
gogs/gogs
< 0.14.3
gogs.io/gogs
0 - 0.14.3Go
Published
Jun 24, 2026
Tracked Since
Jun 25, 2026