Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4355 articles · 196337 vulns · 36/41 feeds (7d)
← Back to list
—
CVE-2026-52810PATCHED
gogs · gogs

Gogs: Write to readonly repositories using receive-pack + service=git-upload-pack confusion

Description

Gogs is an open source self-hosted Git service. Prior to 0.14.3, Git smart HTTP authorizes POST …/git-receive-pack using the client-supplied service query string (so ?service=git-upload-pack is evaluated as read access) while routing still runs git receive-pack, allowing push where only read should be allowed. This vulnerability is fixed in 0.14.3.

Affected Products

VendorProductVersions
gogsgogsgo/gogs.io/gogs: < 0.14.3

References

  • https://github.com/gogs/gogs/security/advisories/GHSA-wmfg-5p4h-5fw3(x_refsource_CONFIRM)
  • https://github.com/gogs/gogs/pull/8331(x_refsource_MISC)
  • https://github.com/gogs/gogs/commit/7c9cf53aca957959bcd98b0cc987d9901b7cb184(x_refsource_MISC)
  • https://github.com/gogs/gogs/releases/tag/v0.14.3(x_refsource_MISC)

Related News (3 articles)

Tier D
The Hacker News3d ago
ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More
→ No new info (linked only)
Tier C
VulDB60d ago
CVE-2026-52810 | Gogs up to 0.14.2 client-supplied Service access control (GHSA-wmfg-5p4h-5fw3)
→ No new info (linked only)
Tier B
BSI Advisories65d ago
[NEU] [kritisch] Gogs: Mehrere Schwachstellen
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
Patch available
gogs.io/gogs@0.14.3
CWECWE-284
PublishedJun 23, 2026
Last enriched60d agov2
Tags
GHSA-wmfg-5p4h-5fw3goCVE-2026-52810
Trending Score33
Source articles3
Independent3
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-52813EXPKEV
Gogs: Path Traversal in organization name results in RCE through Git hooks
Trending: 82
MEDIUMCVE-2026-52795
Gogs: Authorization Bypass in Watch API allows any user to monitor private repository activity
HIGHCVE-2026-52805EXP
Gogs: Migration Redirect Bypass Leads to Internal Repository Theft
CRITICALCVE-2026-52806EXPKEV
Gogs: RCE via git rebase --exec argument injection in pull request merge
HIGHCVE-2026-25119
Gogs: Authentication Bypass via Unvalidated Reverse Proxy Headers

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 23, 2026
Discovered by ZDM
Jun 23, 2026
Updated: severity, tags
Jun 25, 2026
Patch Available
Jun 25, 2026

Version History

v2
Last enriched 60d ago
v2Tier C60d ago

Updated severity to CRITICAL, marked exploit availability as false, and added CVE-2026-52810 as a new tag.

severitytags
via VulDB
v161d ago

Initial creation