目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2026-52801— Gogs 输入验证错误漏洞

CVSS 8.1 · High EPSS 0.57% · P44

Affected Version Matrix 1

ベンダープロダクトVersion Rangeステータス
gogsgogs< 0.14.3affected
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-52801の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
Gogs: Ability to import local repositories via Mirror Settings
ソース: CVE Program / CVE List V5
脆弱性説明
Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Gogs Mirror Settings functionality provide an alternative way from the well protected New Migration functionality for any authenticated users to import local repositories. This issue stems from a lack of validation of SaveAddress function. This vulnerability is fixed in 0.14.3.
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
ソース: CVE Program / CVE List V5
脆弱性タイプ
输入验证不恰当
ソース: CVE Program / CVE List V5
脆弱性タイトル
Gogs 输入验证错误漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Gogs是Gogs团队开源的一个源代码管理软件。 Gogs 0.14.3之前版本存在输入验证错误漏洞,该漏洞源于对SaveAddress函数验证不足,可能导致认证用户通过Mirror Settings功能绕过保护导入本地仓库。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
gogsgogs < 0.14.3 -

II. CVE-2026-52801の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム
Qwen3.6-35B-A3B · 4011 文字数
Pro+限定の内容:
脆弱性再現の録画(実際のサンドボックス構築 + トリガー、限定)
脆弱性の原理を深く分析
トリガー条件と影響範囲
完全な実行可能POCコード
攻撃チェーンと緩和策の提案
POCパッケージのダウンロード
月間100件以上のAI生成枠

III. CVE-2026-52801のインテリジェンス情報

登录查看更多情报信息。

CVE-2026-52801 补丁与修复 (2)

CVE-2026-52801 厂商安全公告 (1)

CVE-2026-52801 厂商页面 (1)

Same Patch Batch · gogs · 2026-06-24 · 24 CVEs total

CVE-2026-5281310.0 CRITICALGogs: Path Traversal in organization name results in RCE through Git hooks
CVE-2026-528069.9 CRITICALGogs: RCE via git rebase --exec argument injection in pull request merge
CVE-2026-527988.9 HIGHGogs: Stored XSS in `.ipynb` Preview
CVE-2026-528008.8 HIGHGogs: CSRF Leading to Organization Owner Takeover
CVE-2026-528058.7 HIGHGogs: Migration Redirect Bypass Leads to Internal Repository Theft
CVE-2026-527978.5 HIGHGogs: Overwriting critical files results in a denial of service
CVE-2026-472678.3 HIGHGogs: SSRF in webhook deliveries
CVE-2026-527997.5 HIGHGogs: Missing Authorization in Attachment Download
CVE-2026-528087.1 HIGHGogs: Write-level collaborators can mutate admin-only repository settings via API
CVE-2026-528096.8 MEDIUMGogs: Password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_
CVE-2026-528025.4 MEDIUMGogs: Open Redirect via redirect_to in Gogs
CVE-2025-647194.9 MEDIUMGogs: Denial of Service in repository/wiki file listing web pages
CVE-2026-527954.3 MEDIUMGogs: Authorization Bypass in Watch API allows any user to monitor private repository acti
CVE-2026-527963.5 LOWGogs: DoS in rendering issue index pattern
CVE-2026-52807Gogs: DOM-based XSS via Milestone Name on New Issue Page
CVE-2026-52810Gogs: Write to readonly repositories using receive-pack + service=git-upload-pack confusio
CVE-2026-52816Gogs: Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leadi
CVE-2026-52814Gogs: Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Des
CVE-2026-52812Gogs: LFS dedupe path leaks private repo content across tenants
CVE-2026-52811Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym

Showing 20 of 24 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2026-52801へのコメント

まだコメントはありません


コメントを残す