Gogs

gogs.io
Gogs

Lightweight self-hosted git platform, written in Go.

Open Source

Gogs Source Code

Author

gogs

Description

The painless way to host your own Git service

#docker#git#go#gogs#mysql#postgresql#raspberry-pi#self-hosted#source-code-management#sqlite3#version-control

Homepage

https://gogs.io

License

MIT

Created

12 Feb 14

Last Updated

29 Jul 26

Latest version

v0.14.3

Primary Language

Go

Size

212,358 KB

Stars

47,701

Forks

5,073

Watchers

47,701

Language Usage

Language Usage

Star History

Star History

Recent Commits

Gogs Security

5.7/10

Repo Security Summary

Updated 13 Jul 26

  • Maintained 10/10
  • Code-Review 1/10
  • Security-Policy 10/10
  • CII-Best-Practices 0/10
  • Dangerous-Workflow 10/10
  • Token-Permissions 0/10
  • Binary-Artifacts 8/10
  • Fuzzing 0/10
  • License 10/10
  • Branch-Protection N/A
  • Signed-Releases 0/10
  • SAST 7/10
  • Packaging 10/10
  • Pinned-Dependencies 8/10

Security Advisories (65)

  • medium Patched CVSS 4.3

    CVE-2026-52795 Authorization Bypass in Watch API allows any user to monitor private repository activity

  • low Patched

    CVE-2026-52815 Unauthenticated Organization Teams Information Disclosure via API

  • medium Patched

    CVE-2026-52814 Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion)

  • critical Patched CVSS 10

    CVE-2026-52813 Path Traversal in organization name results in RCE through Git hooks

  • high Patched

    CVE-2026-52812 LFS dedupe path leaks private repo content across tenants

  • critical Patched

    CVE-2026-52811 UploadRepoFiles writes outside repo working tree via committed parent sym

  • high Patched

    CVE-2026-52810 Write to readonly repositories using receive-pack + service=git-upload-pack confusion

  • high Patched

    GHSA-6vxv-wg6j-5qwp XSS in .ipynb files renderer due to outdated notebookjs

  • low Patched

    CVE-2026-52809 Password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES

  • medium Patched

    CVE-2026-52808 Write-level collaborators can mutate admin-only repository settings via API

  • high Patched

    CVE-2026-52816 Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS

  • high Patched

    CVE-2026-52807 DOM-based XSS via Milestone Name on New Issue Page

  • critical Patched CVSS 9.9

    CVE-2026-52806 RCE via git rebase --exec argument injection in pull request merge

  • high Patched CVSS 8.7

    CVE-2026-52805 Migration Redirect Bypass Leads to Internal Repository Theft

  • high Patched

    CVE-2026-52804 Privilege Escalation via Collaboration Access Mode Validation

  • medium Patched CVSS 5.4

    CVE-2026-52802 Open Redirect via redirect_to

  • high Patched CVSS 8.1

    CVE-2026-52801 Ability to import local repositories via Mirror Settings

  • high Patched CVSS 8.8

    CVE-2026-52800 CSRF Leading to Organization Owner Takeover

  • high Patched CVSS 7.5

    CVE-2026-52799 Missing Authorization in Attachment Download

  • high Patched CVSS 8.9

    CVE-2026-52798 Stored XSS in `.ipynb` Preview

  • high Patched CVSS 7.3

    CVE-2026-26276 DOM-based XSS via milestone selection

  • medium Patched

    CVE-2026-26196 Access tokens get exposed through URL params in API requests

  • medium Patched

    CVE-2026-26195 Stored XSS in branch and wiki views through author and committer names

  • high Patched

    CVE-2026-26194 Release tag option injection in release deletion

  • high Patched CVSS 8.7

    CVE-2026-26022 Stored XSS via data URI in issue comments

  • medium Patched

    CVE-2026-25229 Authorization bypass allows cross-repository label modification

  • medium Patched

    CVE-2026-25119 Authentication Bypass via Unvalidated Reverse Proxy Headers

  • medium Patched

    CVE-2026-25120 Cross-repository comment deletion

  • medium Patched CVSS 6.5

    CVE-2026-23633 Arbitrary file read/write via path traversal in Git hook editing

  • medium Patched CVSS 6.5

    CVE-2026-23632 Update repository content via API with read-only permission

  • high Patched

    CVE-2026-24135 Arbitrary file deletion via path traversal in wiki page update

  • medium Patched CVSS 6.5

    CVE-2026-22592 DoS in repository mirror sync

  • critical Patched

    CVE-2026-25232 Protected branch bypass in web UI

  • medium Patched

    CVE-2025-65852 Authorization bypass in repository deletion API

  • high Patched CVSS 7.3

    GHSA-26gq-grmh-6xm6 Stored XSS via Mermaid diagrams

  • medium Patched CVSS 4.9

    CVE-2025-64719 DoS in repository/wiki file listing pages

  • medium Patched

    CVE-2026-25242 Unauthenticated file upload

  • high Patched

    CVE-2025-64175 2FA bypass via recovery code

  • critical Patched

    CVE-2025-64111 RCE in repository put contents API

  • medium Patched

    CVE-2026-47267 SSRF in webhook deliveries

  • critical Patched CVSS 10

    CVE-2024-56731 Deletion of internal files allows remote command execution

  • high Patched CVSS 7.7

    CVE-2024-39933 Argument Injection when tagging new releases

  • critical Patched CVSS 9.9

    CVE-2024-39932 Argument Injection during changes preview

  • critical Patched CVSS 9.9

    CVE-2024-39931 Deletion of internal files

  • critical Patched CVSS 9.9

    CVE-2024-39930 Argument Injection in the built-in SSH server

  • critical Patched

    CVE-2024-55947 Path Traversal in file update API

  • critical Patched

    CVE-2024-54148 Path Traversal in file editing UI

  • critical Patched CVSS 9.3

    CVE-2026-25921 Cross-repository LFS object overwrite via missing content hash verification

  • medium Patched CVSS 6.3

    CVE-2025-47943 Stored XSS in PDF renderer

  • high Patched CVSS 8.5

    CVE-2026-52797 Overwriting critical files results in a denial of service

  • low Patched CVSS 3.5

    CVE-2026-52796 DoS in rendering issue index pattern

  • critical Patched

    CVE-2022-2024 OS Command Injection in repo editor on case-insensitive file systems

  • critical Patched

    CVE-2022-32174 Stored XSS Assignee

  • high Patched

    CVE-2022-1993 Path Traversal in Git HTTP endpoints

  • critical Patched

    CVE-2022-1992 Path Traversal in file editor on Windows

  • medium Patched

    CVE-2022-31038 XSS vulnerability in repository issue list

  • critical Patched

    CVE-2022-1986 OS Command Injection in file editor

  • critical Patched

    CVE-2021-32546 Remote Command Execution in file editing

  • critical Patched

    CVE-2022-1884 OS Command Injection in file uploading

  • low Patched

    GHSA-pj96-4jhv-v792 XSS in cookies

  • high Patched

    CVE-2022-1285 SSRF in webhook

  • medium Patched

    CVE-2022-1464 Stored XSS in issues

  • critical Patched

    CVE-2022-0415 Remote command execution in file uploading

  • medium Patched

    CVE-2022-0870 SSRF in repository migration

  • medium Patched

    CVE-2022-0871 Improper PAM authorization handling

Gogs Website

Website

Introduction - Gogs: A painless self-hosted Git service

The painless way to host your own Git service

Redirects

Redirects to https://gogs.io/getting-started/introduction

Security Checks

All 65 security checks passed

Server Details

  • IP Address 76.76.21.21
  • Location Walnut, California, United States of America, NA
  • ISP Vercel Inc
  • ASN AS16509

Associated Countries

  • US US

Safety Score

Website marked as safe

100%

Blacklist Check

gogs.io was found on 0 blacklists

  • AntiSocial Blacklist
  • Artists Against 419
  • Badbitcoin
  • Bambenek Consulting
  • CERT Polska
  • CoinBlockerLists
  • CRDF
  • CryptoScamDB
  • EtherAddressLookup
  • EtherScamDB
  • Fake Website Buster
  • MetaMask EthPhishing
  • NABP Not Recommended Sites
  • OpenPhish
  • PetScams
  • PhishFeed
  • PhishFort
  • Phishing.Database
  • PhishStats
  • PhishTank
  • Phishunt
  • RPiList Not Serious
  • Scam.Directory
  • SecureReload Phishing List
  • Spam404
  • StopGunScams
  • Suspicious Hosting IP
  • ThreatFox
  • ThreatLog
  • TweetFeed
  • URLhaus
  • ViriBack C2 Tracker

Website Preview

Website preview

Gogs Reviews

More Code Hosting

About the Data: Gogs

Change History

API

You can access Gogs's data programmatically via our API. Simply make a GET request to:

https://api.awesome-privacy.xyz/v1/services/gogs

The REST API is free, no-auth and CORS-enabled. To learn more, view the API Docs or read the API Usage Guide.

Share Gogs

Help your friends compare Code Hosting, and pick privacy-respecting software and services.
Share Gogs and Awesome Privacy with your network!

View Code Hosting (5)