CVE-2026-22592

Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, an authenticated user can cause a DOS attack. If one of the repo files is deleted before synchronization, it will cause the application to crash. This issue has been patched in versions 0.13.4 and 0.14.0+dev.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gogs:gogs:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:20

Type Values Removed Values Added
Summary
  • (es) Gogs es un servicio Git autoalojado de código abierto. En la versión 0.13.3 y anteriores, un usuario autenticado puede causar un ataque DoS. Si uno de los archivos del repositorio se elimina antes de la sincronización, hará que la aplicación falle. Este problema ha sido parcheado en las versiones 0.13.4 y 0.14.0+dev.

17 Feb 2026, 21:40

Type Values Removed Values Added
References () https://github.com/gogs/gogs/security/advisories/GHSA-cr88-6mqm-4g57 - () https://github.com/gogs/gogs/security/advisories/GHSA-cr88-6mqm-4g57 - Exploit, Vendor Advisory
CPE cpe:2.3:a:gogs:gogs:*:*:*:*:*:*:*:*
First Time Gogs
Gogs gogs

06 Feb 2026, 19:16

Type Values Removed Values Added
References () https://github.com/gogs/gogs/security/advisories/GHSA-cr88-6mqm-4g57 - () https://github.com/gogs/gogs/security/advisories/GHSA-cr88-6mqm-4g57 -

06 Feb 2026, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-06 18:15

Updated : 2026-06-17 10:20


NVD link : CVE-2026-22592

Mitre link : CVE-2026-22592

CVE.ORG link : CVE-2026-22592


JSON object : View

Products Affected

gogs

  • gogs
CWE
CWE-862

Missing Authorization