Sploitus

CVE-2026-52806

3 known exploits for CVE-2026-52806

Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code Execution (RCE) on the server by creating a pull request with a specially crafted branch name that injects the --exec flag into the git rebase command during the "Rebase before merging" merge operation. This vulnerability is fixed in 0.14.3.

Affected products
Gogs
Fix
Available
CVSS 3.1
9.9 CRITICAL
EPSS
7.9% (94th percentile)
Weakness
CWE-77
NVD status
Deferred
Published
2026-06-24
CVE-2026-52806 at NVD
Authoritative description, scoring and affected products

3 known exploits for CVE-2026-52806

Proof-of-concept code and exploit modules indexed by Sploitus