CVE-2026-25120 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Gogs is an open source self-hosted Git service. In versions 0.13.4 and below, the DeleteComment API does not verify that the comment belongs to the repository s…
Medium CVSS: 5.1

CVE-2026-25120

Gogs is an open source self-hosted Git service. In versions 0.13.4 and below, the DeleteComment API does not verify that the comment belongs to the repository specified in the URL. This allows a repository administrator to delete comments from any other repository by supplying arbitrary comment IDs, bypassing authorization controls. The DeleteComment function retrieves a comment by ID without verifying repository ownership and the Database function DeleteCommentByID performs no repository validation. This issue has been fixed in version 0.14.0.
Vendor
Gogs
Product
Gogs
CWE
CWE-639
Yayın Tarihi
2026-02-19 07:17:45
Güncelleme
2026-02-19 19:48:35
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar