Severity
6.5MEDIUMNVD
EPSS
0.6%
top 29.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 1
Latest updateDec 24

Description

Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.8.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages6 packages

NVDgogs/gogs< 0.12.8
Gogogs.io/gogs< 0.12.8
CVEListV5gogs/gogs_gogsunspecified0.12.8

Patches

🔴Vulnerability Details

3
OSV
Server-Side Request Forgery in gogs webhook in gogs.io/gogs2024-08-21
GHSA
Server-Side Request Forgery in gogs webhook2022-06-03
OSV
Server-Side Request Forgery in gogs webhook2022-06-03

📋Vendor Advisories

6
Red Hat
kernel: nvmet-tcp: add bounds check on Transfer Tag2025-12-24
Red Hat
kernel: fs: jfs: fix shift-out-of-bounds in dbDiscardAG2025-09-15
Red Hat
kernel: ntfs3: unhandled page fault in fs/ntfs3/inode.c2023-03-18
Juniper
CVE-2022-22201: An Improper Validation of Specified Index, Position, or Offset in Input vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos2022-10-18
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Application Service Level Management (Apache log4net) — CVE-2018-12852022-10-15