{"id":"CVE-2026-52802","aliases":["GHSA-xxhq-69mf-w8cr","GO-2026-5773"],"url":"https://o3.security/vulnerability/CVE-2026-52802","summary":"Gogs: Open Redirect via redirect_to in Gogs","details":"### Summary\nAn open redirect vulnerability exists in Gogs where attacker-controlled `redirect_to` parameters can bypass validation, allowing redirection to arbitrary external sites.\n\n\n### Details\nAll redirects in Gogs that are validated via the `IsSameSite` function are vulnerable:\n```go\nfunc IsSameSite(url string) bool {\n    return len(url) >= 2 && url[0] == '/' && url[1] != '/' && url[1] != '\\\\'\n}\n```\n\nThe function only inspects the first two characters of the URL string. This check fails to account for directory traversal sequences followed by backslashes. For example:\n```\n/a/../\\example.com\n```\n\nThe `IsSameSite` function checks the input supplied to the `redirect_to` query parameter value `/a/../\\example.com` and considers it valid.\n\nBecause web browsers normalize backslashes `\\` to forward slashes `/`, the normalized URL becomes `//example.com`.\n\nThe normalized URL becomes:\n```\n//example.com\n```\n\nResulting in a cross-origin redirect.\n\nThis affects all endpoints using the `redirect_to` query parameter, including login and other post-action flows.\n\n\n### PoC\n\n1. An attacker can provide a user with a link to login to Gogs with a `redirect_to` query parameter that redirects a user to a site the attacker wants them to visit:\n```\nhttp://192.168.236.132:3000/user/login?redirect_to=/a/../\\example.com\n```\n\n<img width=\"1339\" height=\"536\" alt=\"image\" src=\"https://github.com/user-attachments/assets/3c2a13b8-f0b7-42c2-a223-6f0ebf083589\" />  \n\n<br>\n<br>\n\n2. After the user successfully logs in, they would be redirected to the site an attacker wants them to visit:\n\n<img width=\"1066\" height=\"463\" alt=\"image\" src=\"https://github.com/user-attachments/assets/1726a3d9-6705-43cc-bdd2-90aad105d021\" />\n\n<img width=\"1097\" height=\"396\" alt=\"image\" src=\"https://github.com/user-attachments/assets/376052f5-0e00-4d14-a548-fa75a6269530\" />\n\n\n### Impact\n* Phishing: Attackers can use trusted domain links to redirect victims to credential-harvesting pages\n* OAuth/SSO Token Theft: In authentication flows, authorization codes or tokens may leak via redirect\n* Referer Leakage: Sensitive URL parameters may be exposed to attacker domains via the Referer header\n* Cache Poisoning: In deployments with shared caches, malicious redirects may be cached and served to other users","published":"2026-06-24T20:17:19.805Z","modified":"2026-08-12T03:51:19.621756746Z","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"},"epss":{"score":0.00554,"percentile":0.44942,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"gogs.io/gogs","fixedVersion":"0.14.3"}],"fix":{"url":"https://github.com/gogs/gogs/commit/c5da9631dc75f692f313373ae229c4d47ba6517f","label":"gogs/gogs@c5da963"},"references":[{"type":"WEB","url":"https://github.com/gogs/gogs/releases/tag/v0.14.3"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/52xxx/CVE-2026-52802.json"},{"type":"ADVISORY","url":"https://github.com/gogs/gogs/security/advisories/GHSA-xxhq-69mf-w8cr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-52802"},{"type":"FIX","url":"https://github.com/gogs/gogs/commit/c5da9631dc75f692f313373ae229c4d47ba6517f"},{"type":"FIX","url":"https://github.com/gogs/gogs/pull/8322"},{"type":"PACKAGE","url":"https://github.com/gogs/gogs"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:19.621756746Z"}}