CVE-2026-52801Disclosure

LOWCVSS 8.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Gogs Mirror Settings functionality provide an alternative way from the well protected New Migration functionality for any authenticated users to import local repositories. This issue stems from a lack of validation of SaveAddress function. This vulnerability is fixed in 0.14.3.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-06-23); latest day: 2
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-06-23: 2Mentions · 2026-06-24: 2Technical Details · 2026-06-23: 2Technical Details · 2026-06-24: 106-2306-24
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets4 URLs
Full discourse4 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-52801 Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Gogs Mirror Settings functionality provide an alternative way from the well protected New Migrati… https://www.cve.org/CVERecord?id=CVE-2026-52801 ----- Traducción: CVE-2026-52801 Gog… http://infoflow.cloud`

    Post summary

    The post references the CVE‑2026‑52801 vulnerability in Gogs, noting a pre‑0.14.3 issue with Mirror Settings, but it does not provide detailed technical information, exploitation details, or mitigation steps.

    0000032
    88 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-52801 Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Gogs Mirror Settings functionality provide an alternative way from the well protected New Migrati… https://www.cve.org/CVERecord?id=CVE-2026-52801

    Post summary

    The text announces CVE‑2026‑52801 affecting Gogs, noting a flaw in the Mirror Settings feature before version 0.14.3, but it contains no proof of concept, exploit code, active exploitation reports, or patch details.

    00000804
    57.7K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 Gogs, Unauthenticated Information Disclosure, #CVE-2026-52801 (Medium) -DC-Jun2026-588 https://dailycve.com/gogs-unauthenticated-information-disclosure-cve-2026-52801-medium-dc-jun2026-588/

    Post summary

    A new CVE (CVE‑2026‑52801) for Gogs has been announced, indicating an unauthenticated information disclosure issue with a Medium severity score; no exploit or mitigation details are provided.

    0000052
    216 followersView on X
  • DailyCVE@dailycve
    General

    🟠 Gogs, Improper Input Validation (CWE-20), #CVE-2026-52801 (Medium) -DC-Jun2026-573 https://dailycve.com/gogs-improper-input-validation-cwe-20-cve-2026-52801-medium-dc-jun2026-573/

    Post summary

    The post announces CVE-2026-52801 for Gogs, noting an Improper Input Validation flaw and Medium severity, but offers no PoC, exploit code, active use, or mitigation details.

    0000068
    216 followersView on X

Explore more