CVE Explorer
CVE-2026-52812
Gogs is an open source self-hosted Git service. Prior to 0.14.3, Git LFS storage is content-addressed by OID alone (<LFS-root>/<oid[0]>/<oid[1]>/<oid>) but per-repo authorization lives in the lfs_object table keyed (repo_id, oid). serveUpload skips re-uploading when the OID file already exists on disk and inserts a new (repo_id, oid) row pointing at it without verifying the request body hashes to the OID being claimed. Any user with write access to one repo can bind their repo to an OID owned by
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 3 assertions
{"cweId":"CWE-345","description":"CWE-345: Insufficient Verification of Data Authenticity","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:e655f3d8670ff56703ca5bfb5d6c22484401e88f5abaac07cc83e89598ed01a4 · sha256:419e32a48025fbea… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-862","description":"CWE-862: Missing Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:e655f3d8670ff56703ca5bfb5d6c22484401e88f5abaac07cc83e89598ed01a4 · sha256:419e32a48025fbea… · /containers/cna/problemTypes/2/descriptions/0
{"cweId":"CWE-639","description":"CWE-639: Authorization Bypass Through User-Controlled Key","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:e655f3d8670ff56703ca5bfb5d6c22484401e88f5abaac07cc83e89598ed01a4 · sha256:419e32a48025fbea… · /containers/cna/problemTypes/1/descriptions/0
Affected products and versions
1 source assertion{"product":"gogs","vendor":"gogs","versions":[{"status":"affected","version":"< 0.14.3"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:e655f3d8670ff56703ca5bfb5d6c22484401e88f5abaac07cc83e89598ed01a4 · sha256:419e32a48025fbea… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":7.1,"baseSeverity":"HIGH","privilegesRequired":"LOW","subAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:e655f3d8670ff56703ca5bfb5d6c22484401e88f5abaac07cc83e89598ed01a4 · sha256:419e32a48025fbea… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
3 source assertions{"cweId":"CWE-345","description":"CWE-345: Insufficient Verification of Data Authenticity","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:e655f3d8670ff56703ca5bfb5d6c22484401e88f5abaac07cc83e89598ed01a4 · sha256:419e32a48025fbea… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-862","description":"CWE-862: Missing Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:e655f3d8670ff56703ca5bfb5d6c22484401e88f5abaac07cc83e89598ed01a4 · sha256:419e32a48025fbea… · /containers/cna/problemTypes/2/descriptions/0
{"cweId":"CWE-639","description":"CWE-639: Authorization Bypass Through User-Controlled Key","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:e655f3d8670ff56703ca5bfb5d6c22484401e88f5abaac07cc83e89598ed01a4 · sha256:419e32a48025fbea… · /containers/cna/problemTypes/1/descriptions/0
Source references
5 source assertions{"name":"https://github.com/gogs/gogs/commit/f35a767af74e05342bafc6fdda02c791816426f8","tags":["x_refsource_MISC"],"url":"https://github.com/gogs/gogs/commit/f35a767af74e05342bafc6fdda02c791816426f8"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e655f3d8670ff56703ca5bfb5d6c22484401e88f5abaac07cc83e89598ed01a4 · sha256:419e32a48025fbea… · /containers/cna/references/2
{"name":"https://github.com/gogs/gogs/pull/8333","tags":["x_refsource_MISC"],"url":"https://github.com/gogs/gogs/pull/8333"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e655f3d8670ff56703ca5bfb5d6c22484401e88f5abaac07cc83e89598ed01a4 · sha256:419e32a48025fbea… · /containers/cna/references/1
{"name":"https://github.com/gogs/gogs/releases/tag/v0.14.3","tags":["x_refsource_MISC"],"url":"https://github.com/gogs/gogs/releases/tag/v0.14.3"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e655f3d8670ff56703ca5bfb5d6c22484401e88f5abaac07cc83e89598ed01a4 · sha256:419e32a48025fbea… · /containers/cna/references/3
{"name":"https://github.com/gogs/gogs/security/advisories/GHSA-6p9m-q3jp-47h4","tags":["x_refsource_CONFIRM"],"url":"https://github.com/gogs/gogs/security/advisories/GHSA-6p9m-q3jp-47h4"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e655f3d8670ff56703ca5bfb5d6c22484401e88f5abaac07cc83e89598ed01a4 · sha256:419e32a48025fbea… · /containers/cna/references/0
{"tags":["exploit"],"url":"https://github.com/gogs/gogs/security/advisories/GHSA-6p9m-q3jp-47h4"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e655f3d8670ff56703ca5bfb5d6c22484401e88f5abaac07cc83e89598ed01a4 · sha256:419e32a48025fbea… · /containers/adp/0/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.