Resource exhaustion in gogs - CVE-2026-52814
Published: June 19, 2026
gogs
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the built-in Go SSH server when handling inbound SSH connections without receiving the protocol banner. A remote attacker can open multiple TCP connections and withhold the SSH banner to cause a denial of service.
Only instances using the built-in Go SSH server are vulnerable.