Gogs Vulnerabilities Lead to XSS and Token Leakage Risks
First seen 6 Mar 2026, 00:11 UTC
•
•66.8
Export
Article Content
Browse articles
Gogs, an open source self-hosted Git service, has two critical vulnerabilities prior to version 0.14.2. CVE-2026-26276 allows attackers to execute a DOM-Based XSS via malicious HTML/JavaScript in Milestone names, while CVE-2026-26196 exposes sensitive tokens in URLs, risking data leakage through logs and referrers. Both issues have been patched in version 0.14.2.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Timeline
2026-03-05
CVE-2026-26196 published
2026-03-05
CVE-2026-26276 published
Recent
Patch released for both vulnerabilities
More articles in this cluster
Continue Reading
CISA Directs Agencies to Address Gogs RCE Vulnerability Exploited in Zero-Day Attacks
Gogs 0-Day Vulnerability Exploited in Over 700 Instances
Anonymous Researcher Publishes Zero-Day Exploits for Major Software Projects
Gogs Vulnerability Allows Remote Code Execution via Path Traversal
Critical Zero-Day Vulnerability in Gogs Allows Remote Code Execution
Critical Vulnerabilities in Gogs and Jinjava Require Immediate Patching