CVE-2026-25242: stato di sfruttamento e disponibilità della patch

CVE-2026-25242 · CVSS 9.8 CRITICAL · EPSS 1%

Gogs is an open source self-hosted Git service. Versions 0.13.4 and below expose unauthenticated file upload endpoints by default. When the global RequireSigninView setting is disabled (default), any remote user can upload arbitrary files to the server via /releases/attachments and /issues/attachments. This enables the instance to be abused as a public file host, potentially leading to disk exhaustion, content hosting, or delivery of malware. CSRF tokens do not mitigate this attack due to same-origin cookie issuance. This issue has been fixed in version 0.14.1.

CVE-2026-25242 viene sfruttato?

Quali prodotti e versioni sono interessati?

Nessun elenco di pacchetti interessati registrato qui.

Esiste una patch?

Nessun identificativo di patch registrato qui.

Cosa ha pubblicato PlainSec su CVE-2026-25242

Fonti primarie

Cosa questa scheda non dice

KEV ed EPSS vengono ricontrollati ogni giorno. Scheda aggiornata il 2026-08-11.