
Gogs prior to 0.14.2 is affected by DOM-based XSS via Milestone names (CVE-2026-26276) and token leakage in URLs (CVE-2026-26196). Admins should upgrade to 0.14.2. #AppSec https://threatcluster.io/cluster/gogs-vulnerabilities-lead-to-xss-and-token-leakage-risks-b7d33d9a
Post summary
The post announces Gogs vulnerabilities CVE-2026-26276 and CVE-2026-26196, describes their impact, and urges admins to upgrade to patch version 0.14.2.

