← Back to browse · API

CVE-2026-52806

Severity
CRITICAL
CVSS
9.9
EPSS
0.01464
Risk score
40.11
CISA KEV
No
PoC
Yes
Published
2026-06-24
Modified
2026-06-26
First seen
2026-08-07
Aliases
EUVD-2026-39073, GHSA-QF6P-P7WW-CWR9
Products
gogs:gogs < 0.14.3, linux, suse
Sources
packetstorm e760ebd193aaec6c0d4acb9c|CVE-2026-52806
euvd EUVD-2026-39073

Description

Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code Execution (RCE) on the server by creating a pull request with a specially crafted branch name that injects the --exec flag into the git rebase command during the "Rebase before merging" merge operation. This vulnerability is fixed in 0.14.3.

References