Components
Vulnerabilities
Pricing
MCP
Docs
Sign up
Login
Find vulnerabilities. Fix fast with AI.
Search components by package, version, or CVE to get started.
Ecosystem
Package
Version
Vulnerabilities
CVE-2026-23633
CVE-2026-23633
Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, there is an arbitrary file read/write via path traversal in Git hook editing. This issue has been patched in versions 0.13.4 and 0.14.0+dev.
Published Feb 7, 2026
https://github.com/advisories/GHSA-mrph-w4hh-gx3g
CVSS Score
Medium
6.5
Components Impacted
Components Impacted
Security Details
Security Details
Sonatype Research
Sonatype Research
Ecosystem
Package
Version
Ecosystem
Package
Version
golang
gogs.io/gogs
v0.12.0
golang
gogs.io/gogs
v0.12.10-rc.1
golang
gogs.io/gogs
v0.12.10
golang
gogs.io/gogs
v0.12.11-rc.1
golang
gogs.io/gogs
v0.12.11
golang
gogs.io/gogs
v0.12.1
golang
gogs.io/gogs
v0.12.2
golang
gogs.io/gogs
v0.12.3
golang
gogs.io/gogs
v0.12.4-rc.1
golang
gogs.io/gogs
v0.12.4
golang
gogs.io/gogs
v0.12.5-rc.1
golang
gogs.io/gogs
v0.12.5
golang
gogs.io/gogs
v0.12.6-rc.1
golang
gogs.io/gogs
v0.12.6
golang
gogs.io/gogs
v0.12.7-rc.1
golang
gogs.io/gogs
v0.12.7
golang
gogs.io/gogs
v0.12.8-rc.1
golang
gogs.io/gogs
v0.12.8
golang
gogs.io/gogs
v0.12.9-rc.1
golang
gogs.io/gogs
v0.12.9
golang
gogs.io/gogs
v0.13.0-rc.1
golang
gogs.io/gogs
v0.13.0
golang
gogs.io/gogs
v0.13.1-rc.1
golang
gogs.io/gogs
v0.13.1
golang
gogs.io/gogs
v0.13.2-rc.1
golang
gogs.io/gogs
v0.13.2
golang
gogs.io/gogs
v0.13.3-rc.1
golang
gogs.io/gogs
v0.13.3
1-28 of 28
CVE-2026-23633 | Components Impacted | Sonatype Guide | Sonatype Guide