CVE-2026-25921Disclosure(gogs / gogs)

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch gogs gogs systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Gogs is an open source self-hosted Git service. Prior to version 0.14.2, overwritable LFS object across different repos leads to supply-chain attack, all LFS objects are vulnerable to be maliciously overwritten by malicious attackers. This issue has been patched in version 0.14.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-345

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gogs

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 8 signals
  • Disclosure: 6 classified signals
  • Peaked 5d ago at 2 mentions (2026-03-05); latest day: 1
  • 8 total mentions across 6 days

Affected systems

Vendors
Products
gogs

Deep dive

Activity timeline8 mentions / 6d
01122Mentions · 2026-03-05: 2Mentions · 2026-03-08: 1Mentions · 2026-03-10: 1Mentions · 2026-03-11: 2Mentions · 2026-03-18: 1Mentions · 2026-03-24: 1Patch / Workaround · 2026-03-05: 2Patch / Workaround · 2026-03-11: 2Patch / Workaround · 2026-03-24: 1Technical Details · 2026-03-05: 2Technical Details · 2026-03-08: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-11: 2Technical Details · 2026-03-18: 1Technical Details · 2026-03-24: 103-0503-0803-1003-1103-1803-24
Signal classification2 categories
Disclosure
675.0%
Patch
225.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-052
Disclosure1Patch1
2026-03-081
Disclosure1
2026-03-101
Disclosure1
2026-03-112
Disclosure1Patch1
2026-03-181
Disclosure1
2026-03-241
Disclosure1
Full discourse8 posts
  • Gray Hats@the_yellow_fall
    Disclosure

    A critical 9.3 CVSS flaw (CVE-2026-25921) in Gogs' LFS handling allows attackers to silently overwrite repository files, risking severe supply-chain attacks. #Gogs #CVE #CyberSecurity #SupplyChainAttack #LFS #Vulnerability #InfoSec #AppSec #DevSecOps https://securityonline.info/critical-9-3-cvss-flaw-in-gogs-turns-repositories-into-malware-delivery-vectors/ https://t.co/zHLKOriEQb

    Post summary

    The tweet announces a critical CVSS 9.3 vulnerability (CVE-2026-25921) in Gogs that could let attackers silently overwrite repository files, creating a supply‑chain risk, but it does not provide PoC, exploit, or patch details.

    01051385
    10.6K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical vulnerability (CVE-2026-25921, CVSSv3 9.3) patched in #Gogs. The vulnerability could allow attackers to silently overwrite Git Large File Storage (LFS) objects across repositories. #Patch #Patch #Patch

    Post summary

    The tweet warns of a critical CVE-2026-25921 affecting Gogs, noting it allows attackers to overwrite Git LFS objects but is already patched by the vendor.

    01011385
    7.2K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Gogs の脆弱性 CVE-2026-25921 が FIX:未認証ユーザーによる LFS データ改竄の恐れ https://iototsecnews.jp/2026/03/10/gogs-flaw-could-let-attackers-quietly-overwrite-large-file-storage-data/ この脆弱性 CVE-2026-25921 は、 Git LFS という大きなデータを扱う仕組みにおける、制約と検証の不備に起因します。本来であれば、アップロードされたファイルの真正性をハッシュ値を用いて確認すべきですが、このコンテンツ検証が不十分でした。また、すべてのリポジトリのデータが同じ場所に保存され、既存のファイルを上書きできてしまう設計上の問題も重なっています。これにより、脅威アクターによる他者のファイルの書き換えが可能になっていました。 #CVE202625921 #Gogs #Vulnerability

    Post summary

    The article reports on CVE‑2026‑25921, describing its technical weaknesses in Git LFS that enable unauthenticated file overwrite, but it does not mention any PoC, exploit code, or active attacks, nor does it provide a patch or corrective action.

    01000142
    484 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A critical vulnerability (CVE-2026-25921) in `Gogs` allows cross-repository LFS object overwrites. This impacts data integrity. Assess `Gogs` instances and monitor for patch availability. #InfoSec #GitLFS #Vulnerability https://www.pulsepatch.io/posts/cve-2026-25921-gogs-lfs-overwrite

    Post summary

    A newly disclosed critical vulnerability (CVE‑2026‑25921) in Gogs allows cross‑repository LFS object overwrites, potentially corrupting data; users are advised to check for and apply available patches.

    0000027
    2 followersView on X
  • The Daily Tech Feed@dailytechonx
    Disclosure

    Critical #Gogs vulnerability (CVE-2026-25921) allows silent overwriting of LFS objects, posing severe #SupplyChain risks. No patch yet; implement mitigations immediately. #Security #Hacking Link: https://thedailytechfeed.com/critical-gogs-vulnerability-cve-2026-25921-puts-software-supply-chains-at-risk-no-fix-yet/ #Vulnerability #Exploit #Threat #Mitigation #Alert #Software #DevOps #GitHub #Network #Risk #IT #Intrusion #Protection #Awareness #Incident #Response #Data #Breach

    Post summary

    The tweet announces the disclosure of CVE‑2026‑25921, detailing how it overwrites LFS objects and urges immediate mitigation in the absence of a patch.

    0000015
    259 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-25921 - Critical Gogs is an open source self-hosted Git service. Prior to version 0.14.2, overwritable LFS object across different repos leads to supply-chain attack, all LFS objects are vulnerable to be ... https://www.thehackerwire.com/vulnerability/CVE-2026-25921/ https://t.co/Vmd2TRSYY1

    Post summary

    The post announces a critical vulnerability (CVE-2026-25921) in Gogs, describing the technical flaw and linking to an external resource, but does not provide PoC, exploit code, active exploitation claims, or remediation details.

    0000049
    130 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-25921: CRITICAL] Critical security update: Gogs Git service fixed a vulnerability in version 0.14.2. Upgrade now to prevent supply-chain attacks exploiting overwritable LFS objects. #cybersecurity#cve,CVE-2026-25921,#cybersecurity https://cvefind.com/CVE-2026-25921

    Post summary

    The post announces a critical patch for Gogs 0.14.2, warns of supply‑chain attacks via overwritable LFS objects, and urges immediate upgrade.

    0000044
    598 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25921 Gogs is an open source self-hosted Git service. Prior to version 0.14.2, overwritable LFS object across different repos leads to supply-chain attack, all LFS objects … https://www.cve.org/CVERecord?id=CVE-2026-25921

    Post summary

    The post announces CVE‑2026‑25921, describing an overwrite vulnerability in Gogs LFS objects that could facilitate supply‑chain attacks, and notes that versions newer than 0.14.2 contain a fix.

    0000096
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgogsgogs---

Explore more