Sploitus

CVE-2026-52810

No indexed exploits for CVE-2026-52810 yet

Gogs is an open source self-hosted Git service. Prior to 0.14.3, Git smart HTTP authorizes POST …/git-receive-pack using the client-supplied service query string (so ?service=git-upload-pack is evaluated as read access) while routing still runs git receive-pack, allowing push where only read should be allowed. This vulnerability is fixed in 0.14.3.

Affected products
Gogs
CVSS 4.0
7.1 HIGH
EPSS
0.3% (26th percentile)
Weakness
CWE-284
NVD status
Deferred
Published
2026-06-24
CVE-2026-52810 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-52810 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-52810 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.