HIGH
Gogs: Ability to import local repositories via Mirror Settings
Published Jun 24, 2026
8.1
HIGHCVSS 3.1
EPSS 0.57%
Description
Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Gogs Mirror Settings functionality provide an alternative way from the well protected New Migration functionality for any authenticated users to import local repositories. This issue stems from a lack of validation of SaveAddress function. This vulnerability is fixed in 0.14.3.
Affected products
-
- Version < 0.14.3StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
gogs.io/gogs
Go
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | gogs.io/gogs | 0 | not fixed |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-39070 Advisory
- https://github.com/advisories/GHSA-wv27-2vqp-j7g5 Advisory
- https://github.com/gogs/gogs/commit/11e19f28b5c82466fd1689c94344ef4313ee986c x_refsource_MISC
- https://github.com/gogs/gogs/pull/8225 x_refsource_MISC
- https://github.com/gogs/gogs/releases/tag/v0.14.3 x_refsource_MISC
- https://github.com/gogs/gogs/security/advisories/GHSA-wv27-2vqp-j7g5 exploitx_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-52801
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-39070 | Advisory | |
| https://github.com/advisories/GHSA-wv27-2vqp-j7g5 | Advisory | |
| https://github.com/gogs/gogs/commit/11e19f28b5c82466fd1689c94344ef4313ee986c | x_refsource_MISC | |
| https://github.com/gogs/gogs/pull/8225 | x_refsource_MISC | |
| https://github.com/gogs/gogs/releases/tag/v0.14.3 | x_refsource_MISC | |
| https://github.com/gogs/gogs/security/advisories/GHSA-wv27-2vqp-j7g5 | exploitx_refsource_CONFIRM | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-52801 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jun 24, 2026
Updated Jun 25, 2026
Reserved Jun 8, 2026
Link CVE-2026-52801
CISA Vulnrichment
Updated Jun 25, 2026
ENISA EUVD
EUVD-2026-39070 GHSA-WV27-2VQP-J7G5 Assigner GitHub_M
Published Jun 24, 2026
Updated Jun 25, 2026
Exploited since n/a
Link EUVD-2026-39070