CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-52810

highcovered by 1 sourcefirst seen 2026-06-23
Summary Git smart HTTP authorizes POST …/git-receive-pack using the client-supplied service query string (so ?service=git-upload-pack is evaluated as read access) while routing still runs git receive-pack, allowing push where only read should be allowed. Details Gogs' Git Smart HTTP handler for repository RPCs relies on a client-supplied query parameter to decide which authorization policy to apply. The Git protocol exposes two primary RPCs over HTTP: upload-pack for fetch (read) and receive-pack for push (write). In the affected implementation, the code derives the access mode from the service query parameter (for example, service=git-upload-pack) instead of the actual RPC path being executed. As a result, a request sent to the receive-pack endpoint can be incorrectly treated as a read operation if the query parameter claims it is an upload-pack. This behavior enables a request to POST to the write endpoint (/repo.git/git-receive-pack) while including a query string that indicates a read service. Route dispatch still executes the receive-pack code path, but authorization is evaluated as if the request were a read. A user who is normally only allowed to read a repository, can now write to it. One edge case is fully public repositories, viewable by anonymous users. Since performing this exploit results in a AuthUser property becoming nil in this case, a part of the code that uses it crashes (500 Internal Server Error), making it impossible to exploit. The two situations in which this is vulnerable are: - Attacker = collaborator with only Read rights & victim = owner of the repository - Instance using REQUIRE_SIGNIN_VIEW = true. Attacker = any signed in user & victim = any user with a public repository PoC 1. Create a Gogs instance (eg. http://localhost:3000) with 2 users: victim & attacker 2. As the victim, create a new private repository and add the attacker as a Read collaborator: <img width="1029" height="387" alt="image" src="https://github.com/user-att

⚡ Watch CVE-2026-52810

Get an email if CVE-2026-52810 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-52810

CVE.org record

Embed the live status

CVE-2026-52810 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-52810 status](https://www.csirts.com/badge/CVE-2026-52810)](https://www.csirts.com/cve/CVE-2026-52810)