CVE-2026-25119
Last modified
CVE-2026-25119 is a high-severity vulnerability rated 7.7/10 on the CVSS scale. Gogs is an open source self-hosted Git service. Prior to 0.14.3, when ENABLE_REVERSE_PROXY_AUTHENTICATION is enabled, Gogs accepts the configured authentication header (default: X-WEBAUTH-USER) directly from client requests without validating that the request originated from a trusted reverse proxy. EPSS estimates a 0.86% chance of exploitation in the next 30 days.
Description
Gogs is an open source self-hosted Git service. Prior to 0.14.3, when ENABLE_REVERSE_PROXY_AUTHENTICATION is enabled, Gogs accepts the configured authentication header (default: X-WEBAUTH-USER) directly from client requests without validating that the request originated from a trusted reverse proxy. Any remote attacker who can reach the Gogs service can forge this header to impersonate any user or trigger automatic account creation, completely bypassing authentication. This vulnerability is fixed in 0.14.3.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-25119?
How severe is CVE-2026-25119?
How do I fix CVE-2026-25119?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-25113The WebSocket Application Programming Interface lacks restri…9.8
- CVE-2026-25114The WebSocket Application Programming Interface lacks restri…9.8
- CVE-2026-25115n8n is an open source workflow automation platform. Prior to…9.9
- CVE-2026-25116Runtipi is a personal homeserver orchestrator. Starting in v…8.8
- CVE-2026-25117pwn.college DOJO is an education platform for learning cyber…8.3
- CVE-2026-25118immich is a high performance self-hosted photo and video man…7.5
- CVE-2026-2512The Code Embed plugin for WordPress is vulnerable to Stored …6.4
- CVE-2026-25120Gogs is an open source self-hosted Git service. In versions …2.7
- CVE-2026-25121apko allows users to build and publish OCI container images …7.5
- CVE-2026-25122apko allows users to build and publish OCI container images …5.5
- CVE-2026-25123Homarr is an open-source dashboard. Prior to 1.52.0, a publi…5.3
- CVE-2026-25124OpenEMR is a free and open source electronic health records …6.5
Are you affected by CVE-2026-25119?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
