PT-2026-51459 · Gogs · Gogs

CVE-2026-52801

·

Published

2026-06-23

·

Updated

2026-07-30

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Gogs (affected versions not specified)
Description An information disclosure issue exists in the Mirror Settings functionality, which allows authenticated users to import local repositories from the server filesystem. This occurs due to a lack of validation in the SaveAddress() function, bypassing the protections implemented in the New Migration feature. This flaw enables access to any repository the git user has permissions to view and may also lead to blind Server-Side Request Forgery (SSRF), a condition where the server is induced to make requests to an unintended location without returning the response to the attacker.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-52801
GHSA-WV27-2VQP-J7G5
GO-2026-5724
OPENSUSE-SU-2026:21483-1

Affected Products

Gogs