CVE-2025-64719Disclosure

LOWCVSS 4.9 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Gogs is an open source self-hosted Git service. Prior to 0.14.3, a malicious user with rights to create a new file on a repository or wiki page can trigger a denial of service condition in which the pages containing the listing of files will return HTTP error 500 and render the web interface unusable for the repository or wiki. The issue is present in file internal/route/repo/wiki.go and internal/route/repo/view.go where the pages try to recover commit information. If errors are returned while recovering commit information, the page will return a 500 error and stop rendering, resulting in a denial of service. This vulnerability is fixed in 0.14.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-24: 2Patch / Workaround · 2026-06-24: 1Technical Details · 2026-06-24: 206-24
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-64719 Gogs is an open source self-hosted Git service. Prior to 0.14.3, a malicious user with rights to create a new file on a repository or wiki page can trigger a denial o… https://www.cve.org/CVERecord?id=CVE-2025-64719 ----- Traducción: CVE-2025-64719 Gog… http://infoflow.cloud`

    Post summary

    The post announces CVE-2025-64719 in Gogs, highlighting a denial‑of‑service flaw where users with file‑creation rights can trigger an issue, and notes that the problem was fixed in version 0.14.3.

    0000036
    88 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-64719 Gogs is an open source self-hosted Git service. Prior to 0.14.3, a malicious user with rights to create a new file on a repository or wiki page can trigger a denial o… https://www.cve.org/CVERecord?id=CVE-2025-64719

    Post summary

    The text announces a denial‑of‑service flaw in Gogs older than v0.14.3, explaining the vulnerability’s basic mechanics, but does not provide PoC, exploit, or patch details.

    00000726
    57.7K followersView on X

Explore more