Incorrect authorization in gogs - CVE-2026-25232

 

Incorrect authorization in gogs - CVE-2026-25232

Published: April 27, 2026


Vulnerability identifier: #VU128091
CSH Severity: Medium
CVSS v4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-25232
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass branch protection and delete protected branches.

The vulnerability exists due to improper access control in the DeleteBranchPost function in the web interface when handling direct POST requests to branch deletion endpoints. A remote user can send a specially crafted POST request to bypass branch protection and delete protected branches.

The issue affects repository collaborators with Write permissions and can also be used to delete the default branch because the web deletion path does not trigger the Git Hook layer checks.


Affected software

gogs

How to mitigate CVE-2026-25232

Install security update from vendor's website.

gogs - update to 0.14.0

External References

Related Security Bulletins