CVE-2026-25229

Gogs is an open source self-hosted Git service. Versions 0.13.4 and below have a broken access control vulnerability which allows authenticated users with write access to any repository to modify labels belonging to other repositories. The UpdateLabel function in the Web UI (internal/route/repo/issue.go) fails to verify that the label being modified belongs to the repository specified in the URL path, enabling cross-repository label tampering attacks. The vulnerability exists in the Web UI's label update endpoint POST /:username/:reponame/labels/edit. The handler function UpdateLabel uses an incorrect database query function that bypasses repository ownership validation. This issue has been fixed in version 0.14.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gogs:gogs:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:24

Type Values Removed Values Added
References () https://github.com/gogs/gogs/security/advisories/GHSA-cv22-72px-f4gh - Exploit, Vendor Advisory, Mitigation () https://github.com/gogs/gogs/security/advisories/GHSA-cv22-72px-f4gh - Exploit, Mitigation, Vendor Advisory
Summary
  • (es) Gogs es un servicio Git de código abierto autoalojado. Las versiones 0.13.4 e inferiores tienen una vulnerabilidad de control de acceso roto que permite a usuarios autenticados con acceso de escritura a cualquier repositorio modificar etiquetas pertenecientes a otros repositorios. La función UpdateLabel en la interfaz de usuario web (Web UI) (internal/route/repo/issue.go) no verifica que la etiqueta que se está modificando pertenezca al repositorio especificado en la ruta URL, lo que permite ataques de manipulación de etiquetas entre repositorios. La vulnerabilidad existe en el endpoint de actualización de etiquetas de la interfaz de usuario web (Web UI) POST /:username/:reponame/labels/edit. La función gestora UpdateLabel utiliza una función de consulta de base de datos incorrecta que omite la validación de propiedad del repositorio. Este problema ha sido corregido en la versión 0.14.1.

19 Feb 2026, 19:45

Type Values Removed Values Added
References () https://github.com/gogs/gogs/commit/643a6d6353cb6a182a4e1f0720228727f30a3ad2 - () https://github.com/gogs/gogs/commit/643a6d6353cb6a182a4e1f0720228727f30a3ad2 - Patch
References () https://github.com/gogs/gogs/security/advisories/GHSA-cv22-72px-f4gh - () https://github.com/gogs/gogs/security/advisories/GHSA-cv22-72px-f4gh - Exploit, Vendor Advisory, Mitigation
CPE cpe:2.3:a:gogs:gogs:*:*:*:*:*:*:*:*
First Time Gogs
Gogs gogs
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

19 Feb 2026, 07:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-19 07:17

Updated : 2026-06-17 10:24


NVD link : CVE-2026-25229

Mitre link : CVE-2026-25229

CVE.ORG link : CVE-2026-25229


JSON object : View

Products Affected

gogs

  • gogs
CWE
CWE-284

Improper Access Control