logo

Gogs Flaw Could Let Attackers Quietly Overwrite Large File Storage Data

ID: 78594dd5-e718-5574-8eb1-9ca3c00f084b

STIX ID: report--78594dd5-e718-5574-8eb1-9ca3c00f084b

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-03-10

Date Updated: 2026-04-22

Author: Divya

...
...

**CVE-2026-25921 — Critical Gogs LFS overwrite flaw:** A failure to verify uploaded Git LFS object content combined with a global object store in Gogs (versions 0.14.1 and earlier) enables unauthenticated actors to overwrite LFS files across repositories, allowing silent supply-chain compromises; the issue is fixed in Gogs 0.14.2 and administrators should upgrade immediately, validate existing LFS objects for tampering, and restrict access until patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.