CVE-2026-52810Patch

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Gogs is an open source self-hosted Git service. Prior to 0.14.3, Git smart HTTP authorizes POST …/git-receive-pack using the client-supplied service query string (so ?service=git-upload-pack is evaluated as read access) while routing still runs git receive-pack, allowing push where only read should be allowed. This vulnerability is fixed in 0.14.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-06-23); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-06-23: 1Mentions · 2026-08-28: 1Mentions · 2026-09-07: 1Patch / Workaround · 2026-08-28: 1Patch / Workaround · 2026-09-07: 1Technical Details · 2026-06-23: 1Technical Details · 2026-08-28: 1Technical Details · 2026-09-07: 106-2308-2809-07
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-06-231
Disclosure1
2026-08-281
Patch1
2026-09-071
Patch1
Full discourse3 posts
  • Aikido@AikidoSecurity
    Patch

    We also reported a logic bug that lets you write to read-only repositories (CVE-2026-52810) and an XSS in the Jupyter rendering library Gogs was using. One bypass we reported is still unpatched, so we include a manual code patch in the blog post. Gogs isn't actively maintained right now, so we recommend a different self-hosted Git solution for the time being.

    Post summary

    The post reports a logic bug and XSS in Gogs, notes that the bypass remains unpatched, provides a manual code patch, and advises switching to another self‑hosted Git solution.

    01030719
    17.5K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Gogs の脆弱性 CVE-2026-52813/52810 が FIX:パス・トラバーサルによる RCE の恐れ https://iototsecnews.jp/2026/08/29/critical-gogs-flaw-enables-remote-code-execution-through-path-traversal/ セルフホスト型 Git サービスの Gogs において、識別子の検証不備や認可処理の曖昧さに起因する重大な不具合が判明しました。攻撃者によるパスの走査/システム上での任意のコマンド実行/書き込み権限のない領域への不正なデータ保存などの被害が生じる恐れがあります。これらの不具合には CVE-2026-52813/CVE-2026-52810 が割り振られております。システムへの深刻な影響を防ぐためにも、修正が適用された最新バージョンへのアップデートや、不審な設定値の確認といった適切な処置が強く求められます。 #CVE202652810 #CVE202652813 #Gogs #Vulnerability

    Post summary

    Gogs has been found vulnerable to CVE‑2026‑52813 and CVE‑2026‑52810, allowing remote code execution via path traversal; the advisory urges users to apply the latest patch and review configuration settings.

    00000140
    513 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Gogs, Authorization Bypass, #CVE-2026-52810 (High Severity) -DC-Jun2026-584 https://dailycve.com/gogs-authorization-bypass-cve-2026-52810-high-severity-dc-jun2026-584/

    Post summary

    The passage announces a high‑severity authorization bypass vulnerability (CVE-2026‑52810) in Gogs, but it provides no PoC, exploit, or patch details.

    0000039
    216 followersView on X

Explore more