{"id":"CVE-2026-47267","aliases":["GHSA-c4v7-xg93-qf8g","GO-2026-5312"],"url":"https://o3.security/vulnerability/CVE-2026-47267","summary":"Gogs: SSRF in webhook deliveries","details":"Gogs is an open source self-hosted Git service. Prior to 0.14.3, the fix for CVE-2022-1285 prevents adding webooks or running webhooks with URLs with a hostname that resolves in localCIDRs. However, webhooks still follow redirects allowing to access hostname inside localCIDRs. This vulnerability is fixed in 0.14.3.","published":"2026-06-24T20:09:02.854Z","modified":"2026-08-12T03:51:42.949829253Z","cvss":{"score":8.3,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L"},"epss":{"score":0.0032,"percentile":0.24548,"asOf":"2026-08-12"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"gogs.io/gogs","fixedVersion":"0.14.3"}],"fix":{"url":"https://github.com/gogs/gogs/commit/199cf4fd5bbe40b92f6dc8d649e241fd7a8d0018","label":"gogs/gogs@199cf4f"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47267.json"},{"type":"ADVISORY","url":"https://github.com/gogs/gogs/security/advisories/GHSA-c4v7-xg93-qf8g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47267"},{"type":"FIX","url":"https://github.com/gogs/gogs/commit/199cf4fd5bbe40b92f6dc8d649e241fd7a8d0018"},{"type":"FIX","url":"https://github.com/gogs/gogs/pull/8263"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:42.949829253Z"}}