CVE-2018-15178: Gogs

Medium severity, CVSS 6.1. EPSS: 1.3% chance of exploitation in the next 30 days.

Open redirect vulnerability in Gogs before 0.12 allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks via an initial /\ substring in the user/login redirect_to parameter, related to the function isValidRedirect in routes/user/auth.go.

Affected products

  • Gogs Gogs: before 0.12 (fixed in 0.12)

Published 2018-08-08. Last modified 2026-06-17.