CVE-2026-25232Disclosure(gogs / gogs)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch gogs gogs systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Gogs is an open source self-hosted Git service. Versions 0.13.4 and below have an access control bypass vulnerability which allows any repository collaborator with Write permissions to delete protected branches (including the default branch) by sending a direct POST request, completely bypassing the branch protection mechanism. This vulnerability in the DeleteBranchPost function eenables privilege escalation from Write to Admin level, allowing low-privilege users to perform dangerous operations that should be restricted to administrators only. Although Git Hook layer correctly prevents protected branch deletion via SSH push, the web interface deletion operation does not trigger Git Hooks, resulting in complete bypass of protection mechanisms. In oder to exploit this vulnerability, attackers must have write permissions to the target repository, protected branches configured to the target repository and access to the Gogs web interface. This issue has been fixed in version 0.14.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gogs

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-02-23); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
gogs

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-23: 1Mentions · 2026-04-27: 1Patch / Workaround · 2026-04-27: 1Technical Details · 2026-02-23: 1Technical Details · 2026-04-27: 102-2304-27
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-25232 Gogs is an open source self-hosted Git service. Versions 0.13.4 and below have an access control bypass vulnerability which allows any repository collaborator with Wr… https://www.cve.org/CVERecord?id=CVE-2026-25232

    Post summary

    CVE-2026-25232 is an access control bypass in Gogs 0.13.4 and earlier, allowing repository collaborators with write access to circumvent restrictions.

    000201.8K
    56.5K followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: High access control bypass vulnerability in #Gogs. CVE-2026-25232 CVSS: 8.8. This can allow collaborators with write permissions to delete protected branches #Patch #Patch #Patch

    Post summary

    The text announces a high‑severity access control bypass in Gogs (CVE-2026-25232, CVSS 8.8) that lets collaborators with write permissions delete protected branches, and indicates that a patch is available.

    01000194
    7.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgogsgogs---

Explore more