logo

Gogs Vulnerability Enables Attackers to Silently Overwrite Large File Storage Objects

ID: 3ddea4c1-3a59-5dde-b7e4-3d985429e7ed

STIX ID: report--3ddea4c1-3a59-5dde-b7e4-3d985429e7ed

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-03-11

Date Updated: 2026-04-21

Author: Abinaya

...
...

A critical vulnerability (CVE-2026-25921, CVSS 3.1 score 10.0) in Gogs (<= 0.14.1) lets attackers overwrite shared Large File Storage (LFS) objects by uploading a manipulated file that claims a victim’s SHA-256 OID; because storage is not isolated by repository and uploads are not verified, this enables undetectable supply-chain tampering across repositories. No official patch was available at disclosure; recommended temporary mitigations include restricting LFS upload permissions and performing manual SHA-256 integrity checks until server-side hash verification is implemented.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.