CVE-2020-9329: Gogs

Medium severity, CVSS 5.9. EPSS: 0.8% chance of exploitation in the next 30 days.

Gogs through 0.11.91 allows attackers to violate the admin-specified repo-creation policy due to an internal/db/repo.go race condition.

Affected products

  • Gogs Gogs: up to and including 0.11.91

Published 2020-02-21. Last modified 2026-06-17.