🔐 CVE Alert

CVE-2026-52810

UNKNOWN 0.0

Gogs: Write to readonly repositories using receive-pack + service=git-upload-pack confusion

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Gogs is an open source self-hosted Git service. Prior to 0.14.3, Git smart HTTP authorizes POST …/git-receive-pack using the client-supplied service query string (so ?service=git-upload-pack is evaluated as read access) while routing still runs git receive-pack, allowing push where only read should be allowed. This vulnerability is fixed in 0.14.3.

CWE CWE-284
Vendor gogs
Product gogs
Published Jun 24, 2026
Last Updated Jun 24, 2026
Stay Ahead of the Next One

Get instant alerts for gogs gogs

Be the first to know when new unknown vulnerabilities affecting gogs gogs are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

gogs / gogs
< 0.14.3

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/gogs/gogs/security/advisories/GHSA-wmfg-5p4h-5fw3 github.com: https://github.com/gogs/gogs/pull/8331 github.com: https://github.com/gogs/gogs/commit/7c9cf53aca957959bcd98b0cc987d9901b7cb184 github.com: https://github.com/gogs/gogs/releases/tag/v0.14.3