Remote Code Execution Vulnerability in Gogs by Gogs
CVE-2026-52806

9.9CRITICAL

Key Information:

Vendor

Gogs

Status
Vendor
CVE Published:
24 June 2026

What is CVE-2026-52806?

Gogs, an open source self-hosted Git service, has a vulnerability that allows authenticated users to execute remote code on the server. This occurs when a specially crafted pull request is made, containing a branch name that injects the --exec flag into the git rebase command during the 'Rebase before merging' operation. This critical flaw impacts the performance and security of Gogs installations prior to version 0.14.3. Users are encouraged to upgrade to version 0.14.3 or later for a fix.

Affected Version(s)

gogs < 0.14.3

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.