PatchSiren cyber security CVE debrief
CVE-2025-64719 gogs CVE debrief
A denial of service vulnerability exists in Gogs, a self-hosted Git service, prior to version 0.14.3. A malicious user with rights to create a new file on a repository or wiki page can trigger a denial of service condition, rendering the web interface unusable for the repository or wiki. The issue is present in file internal/route/repo/wiki.go and internal/route/repo/view.go where the pages try to recover commit information. If errors are returned while recovering commit information, the page will return a 500 error and stop rendering, resulting in a denial of service. This vulnerability is fixed in 0.14.3.
- Vendor
- gogs
- Product
- Unknown
- CVSS
- MEDIUM 4.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-24
- Original CVE updated
- 2026-10-05
- Advisory published
- 2026-06-24
- Advisory updated
- 2026-10-05
Who should care
Defenders responsible for Gogs instances should assess exposure and apply the patch to prevent potential denial of service attacks. Defenders should prioritize verifying exposure and applying the patch to prevent potential denial of service attacks against Gogs instances. The vulnerability can be triggered by a malicious user with rights to create a new file on a repository or wiki page, rendering the web interface unusable for the repository or wiki.
Why it matters
Defenders should prioritize verifying exposure and applying the patch to prevent potential denial of service attacks against Gogs instances. The vulnerability can be triggered by a malicious user with rights to create a new file on a repository or wiki page, rendering the web interface unusable.
- Potential denial of service attacks against Gogs instances.
- Unavailability of the web interface for repositories or wikis.
Technical summary
A malicious user with rights to create a new file on a repository or wiki page can trigger a denial of service condition in which the pages containing the listing of files will return HTTP error 500 and render the web interface unusable for the repository or wiki. The issue is present in file internal/route/repo/wiki.go and internal/route/repo/view.go where the pages try to recover commit information. If errors are returned while recovering commit information, the page will return a 500 error and stop rendering, resulting in a denial of service. This vulnerability is fixed in 0.14.3.
Defensive priority
Defenders should prioritize verifying exposure and applying the patch to prevent potential denial of service attacks.
Recommended defensive actions
- Verify exposure by checking if the Gogs instance is running a version prior to 0.14.3.
- Apply the patch by upgrading to version 0.14.3 or later.
- Monitor for potential denial of service attacks.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The vulnerability is present in file internal/route/repo/wiki.go and internal/route/repo/view.go. The issue is fixed in version 0.14.3. The vulnerability can be triggered by a malicious user with rights to create a new file on a repository or wiki page, rendering the web interface unusable for the repository or wiki. Defenders should verify exposure and apply the patch to prevent potential denial of service attacks.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-64719 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-64719
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-64719 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-64719
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/gogs/gogs/security/advisories/GHSA-3qq3-668m-v9mj
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.