Gogs is an open source self-hosted Git service. Prior to 0.14.3, the fix for CVE-2022-1285 prevents adding webooks or running webhooks with URLs with a hostname that resolves in localCIDRs. However, webhooks still follow redirects allowing to access hostname inside localCIDRs. This vulnerability is fixed in 0.14.3.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-06-24 21:16
Updated : 2026-06-25 14:19
NVD link : CVE-2026-47267
Mitre link : CVE-2026-47267
CVE.ORG link : CVE-2026-47267
JSON object : View
Products Affected
No product.
CWE
CWE-918
Server-Side Request Forgery (SSRF)
