Go package intelligence
gogs.io/gogs Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting the Go package gogs.io/gogs, including the gap beyond CISA KEV, confidence assessments, and sensor observations.
- Total KEVs
- 3
- Known exploited vulnerabilities affecting gogs.io/gogs
- In CISA KEV
- 1
- Records also listed in the official catalog
- Beyond CISA KEV
- 2
- Additional exploited vulnerabilities absent from CISA KEV
- Sensor Observed
- 2
- gogs.io/gogs KEVs with sensor-observed exploitation activity
Review gogs.io/gogs exploitation against the versions you run
Two of the three exploited gogs.io/gogs vulnerabilities tracked here are not in CISA KEV.
- 33%
- Covered by CISA
- 67%
- Beyond CISA
Attested gogs.io/gogs vulnerabilities
3 known exploited vulnerabilities affecting this package.
| Vulnerability | CISA KEV | Added |
|---|---|---|
|
CVE-2026-52806
Gogs: RCE via git rebase --exec argument injection in pull request merge |
Beyond CISA | 17 Aug 2026 |
|
CVE-2026-52813
Gogs: Path Traversal in organization name results in RCE through Git hooks |
Beyond CISA | 30 Jun 2026 |
|
CVE-2025-8110
File overwrite in file update API in Gogs |
In CISA | 01 Jun 2026 |
Recurring weakness patterns
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Relative Path Traversal, and Improper Neutralization of Special Elements used in a Command ('Command Injection') account for mapped occurrences across this gogs.io/gogs KEV portfolio.