๐Ÿ” CVE Alert

CVE-2026-25232

UNKNOWN 0.0

Gogs has a Protected Branch Deletion Bypass in Web Interface

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Gogs is an open source self-hosted Git service. Versions 0.13.4 and below have an access control bypass vulnerability which allows any repository collaborator with Write permissions to delete protected branches (including the default branch) by sending a direct POST request, completely bypassing the branch protection mechanism. This vulnerability in the DeleteBranchPost function eenables privilege escalation from Write to Admin level, allowing low-privilege users to perform dangerous operations that should be restricted to administrators only. Although Git Hook layer correctly prevents protected branch deletion via SSH push, the web interface deletion operation does not trigger Git Hooks, resulting in complete bypass of protection mechanisms. In oder to exploit this vulnerability, attackers must have write permissions to the target repository, protected branches configured to the target repository and access to the Gogs web interface. This issue has been fixed in version 0.14.1.

CWE CWE-863
Vendor gogs
Product gogs
Published Feb 19, 2026
Last Updated Feb 19, 2026
Stay Ahead of the Next One

Get instant alerts for gogs gogs

Be the first to know when new unknown vulnerabilities affecting gogs gogs are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

gogs / gogs
< 0.14.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/gogs/gogs/security/advisories/GHSA-2c6v-8r3v-gh6p github.com: https://github.com/gogs/gogs/pull/8124 github.com: https://github.com/gogs/gogs/commit/7b7e38c88007a7c482dbf31efff896185fd9b79c github.com: https://github.com/gogs/gogs/releases/tag/v0.14.1