CVE-2026-26196Disclosure(gogs / gogs)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch gogs gogs systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Gogs is an open source self-hosted Git service. Prior to version 0.14.2, gogs api still accepts tokens in url params like token and access_token, which can leak through logs, browser history, and referrers. This issue has been patched in version 0.14.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-598

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gogs

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-03-05); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
gogs

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Patch / Workaround · 2026-03-06: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 103-0503-06
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • ThreatCluster@threatcluster
    Disclosure

    Gogs prior to 0.14.2 is affected by DOM-based XSS via Milestone names (CVE-2026-26276) and token leakage in URLs (CVE-2026-26196). Admins should upgrade to 0.14.2. #AppSec https://threatcluster.io/cluster/gogs-vulnerabilities-lead-to-xss-and-token-leakage-risks-b7d33d9a

    Post summary

    The post announces Gogs vulnerabilities CVE-2026-26276 and CVE-2026-26196, describes their impact, and urges admins to upgrade to patch version 0.14.2.

    0000078
    93 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26196 Gogs is an open source self-hosted Git service. Prior to version 0.14.2, gogs api still accepts tokens in url params like token and access_token, which can leak throu… https://www.cve.org/CVERecord?id=CVE-2026-26196

    Post summary

    The post discloses that Gogs API accepted tokens in URL parameters before v0.14.2, potentially leaking credentials, but does not provide a PoC, exploit, or evidence of active exploitation.

    0000092
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgogsgogs---

Explore more