Input validation error in gogs - CVE-2026-52796
Published: June 19, 2026
gogs
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper input validation in the issue index pattern rendering logic in internal/markup/markup.go when rendering issue index patterns. A remote user can configure a specially crafted issue index pattern and trigger its rendering to cause a denial of service.
User interaction is required to access a page that renders the affected issue index.