CVE-2026-52799Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Gogs is an open source self-hosted Git service. Prior to 0.14.3, GET /attachments/:uuid returns the raw attachment file without verifying whether the requester has view permission for the associated Issue/Comment/Release or the repository. In a test environment with REQUIRE_SIGNIN_VIEW = false, we confirmed that an unauthenticated user can download attachments belonging to a private repository. This vulnerability is fixed in 0.14.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-06-24)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-23: 1Mentions · 2026-06-24: 2Patch / Workaround · 2026-06-24: 1Technical Details · 2026-06-23: 1Technical Details · 2026-06-24: 206-2306-24
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-231
Disclosure1
2026-06-242
Disclosure2
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-52799 Gogs is an open source self-hosted Git service. Prior to 0.14.3, GET /attachments/:uuid returns the raw attachment file without verifying whether the requester has vi… https://www.cve.org/CVERecord?id=CVE-2026-52799 ----- Traducción: CVE-2026-52799 Gog… http://infoflow.cloud`

    Post summary

    The text announces CVE‑2026‑52799: Gogs versions prior to 0.14.3 expose raw attachment files via GET /attachments/:uuid without proper access checks.

    0000039
    88 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-52799 Gogs is an open source self-hosted Git service. Prior to 0.14.3, GET /attachments/:uuid returns the raw attachment file without verifying whether the requester has vi… https://www.cve.org/CVERecord?id=CVE-2026-52799

    Post summary

    The post references CVE-2026-52799, highlighting that versions prior to 0.14.3 allow unauthorized access to attachments, and notes that newer releases address the issue, but no PoC or exploitation details are provided.

    00000907
    57.7K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 Gogs, Missing Authorization Vulnerability, #CVE-2026-52799 (Medium) -DC-Jun2026-575 https://dailycve.com/gogs-missing-authorization-vulnerability-cve-2026-52799-medium-dc-jun2026-575/

    Post summary

    The post announces CVE‑2026‑52799, a medium‑severity missing‑authorization vulnerability in Gogs, but provides no PoC, exploit code, active exploitation evidence, or patch details.

    0000048
    216 followersView on X

Explore more