CVE-2019-14544: Gogs

Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.

routes/api/v1/api.go in Gogs 0.11.86 lacks permission checks for routes: deploy keys, collaborators, and hooks.

Affected products

  • Gogs Gogs: version 0.11.86 only

Published 2019-08-02. Last modified 2026-06-17.