Skip to content
Gogs Vulnerabilities Lead to XSS and Token Leakage Risks

Gogs Vulnerabilities Lead to XSS and Token Leakage Risks

First seen 6 Mar 2026, 00:11 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 16:10 UTC

Gogs, an open source self-hosted Git service, has two critical vulnerabilities prior to version 0.14.2. CVE-2026-26276 allows attackers to execute a DOM-Based XSS via malicious HTML/JavaScript in Milestone names, while CVE-2026-26196 exposes sensitive tokens in URLs, risking data leakage through logs and referrers. Both issues have been patched in version 0.14.2.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

Timeline

2026-03-05
CVE-2026-26196 published
2026-03-05
CVE-2026-26276 published
Recent
Patch released for both vulnerabilities

More articles in this cluster (4)

Following this threat?

Track Gogs and CVE-2026-26194 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed