Back to Database
Status published
High
CVE-2018-16409
In Gogs 0.11.53, an attacker can use migrate to send...
Vulnerability Description
In Gogs 0.11.53, an attacker can use migrate to send arbitrary HTTP GET requests, leading to SSRF.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-16409
Credits & Attribution
No credits recorded in the NVD database.
References
More from gogs
View All →CVE-2025-64719
Gogs: Denial of Service in repository/wiki file listing web pages
Medium
4.9
CVE-2025-64175
Gogs Vulnerable to 2FA Bypass via Recovery Code
High
7.7
CVE-2025-64111
Gogs's update .git/config file allows remote command execution
Critical
9.3
CVE-2025-47943
Gogs stored XSS in PDF renderer
Medium
6.3
CVE-2024-56731
Gogs deletion of internal files allows remote command execution
Critical
10
Affected Vendor
gogs
View all reports →Affected Software
gogs
Vulnerable Versions:
0.11.53
Timeline
Official Publish:
September 3rd, 2018
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.