CVE-2026-26276
- EPSS -
- Veröffentlicht 05.03.2026 18:51:13
- Zuletzt bearbeitet 05.03.2026 22:00:00
Gogs is an open source self-hosted Git service. Prior to version 0.14.2, an attacker can store an HTML/JavaScript payload in a repository’s Milestone name, and when another user selects that Milestone on the New Issue page (/issues/new), a DOM-Based ...
CVE-2026-26196
- EPSS -
- Veröffentlicht 05.03.2026 18:49:19
- Zuletzt bearbeitet 05.03.2026 22:04:11
Gogs is an open source self-hosted Git service. Prior to version 0.14.2, gogs api still accepts tokens in url params like token and access_token, which can leak through logs, browser history, and referrers. This issue has been patched in version 0.14...
CVE-2026-26195
- EPSS -
- Veröffentlicht 05.03.2026 18:40:31
- Zuletzt bearbeitet 05.03.2026 19:38:33
Gogs is an open source self-hosted Git service. Prior to version 0.14.2, stored xss is still possible through unsafe template rendering that mixes user input with safe plus permissive sanitizer handling of data urls. This issue has been patched in ve...
CVE-2026-26194
- EPSS -
- Veröffentlicht 05.03.2026 18:38:38
- Zuletzt bearbeitet 05.03.2026 19:38:33
Gogs is an open source self-hosted Git service. Prior to version 0.14.2, there's a security issue in gogs where deleting a release can fail if a user controlled tag name is passed to git without the right separator, this lets git options get injected...
CVE-2026-25921
- EPSS -
- Veröffentlicht 05.03.2026 18:36:30
- Zuletzt bearbeitet 05.03.2026 19:38:33
Gogs is an open source self-hosted Git service. Prior to version 0.14.2, overwritable LFS object across different repos leads to supply-chain attack, all LFS objects are vulnerable to be maliciously overwritten by malicious attackers. This issue has ...
CVE-2026-26022
- EPSS -
- Veröffentlicht 05.03.2026 18:34:12
- Zuletzt bearbeitet 05.03.2026 19:38:33
Gogs is an open source self-hosted Git service. Prior to version 0.14.2, a stored cross-site scripting (XSS) vulnerability exists in the comment and issue description functionality. The application's HTML sanitizer explicitly allows data: URI schemes...
CVE-2026-25229
- EPSS 0.03%
- Veröffentlicht 19.02.2026 02:33:09
- Zuletzt bearbeitet 19.02.2026 19:45:35
Gogs is an open source self-hosted Git service. Versions 0.13.4 and below have a broken access control vulnerability which allows authenticated users with write access to any repository to modify labels belonging to other repositories. The UpdateLabe...
CVE-2026-25242
- EPSS 0.06%
- Veröffentlicht 19.02.2026 02:28:40
- Zuletzt bearbeitet 19.02.2026 19:46:19
Gogs is an open source self-hosted Git service. Versions 0.13.4 and below expose unauthenticated file upload endpoints by default. When the global RequireSigninView setting is disabled (default), any remote user can upload arbitrary files to the serv...
CVE-2026-25232
- EPSS 0.04%
- Veröffentlicht 19.02.2026 02:25:34
- Zuletzt bearbeitet 19.02.2026 19:44:07
Gogs is an open source self-hosted Git service. Versions 0.13.4 and below have an access control bypass vulnerability which allows any repository collaborator with Write permissions to delete protected branches (including the default branch) by sendi...
CVE-2026-25120
- EPSS 0.03%
- Veröffentlicht 19.02.2026 01:59:39
- Zuletzt bearbeitet 19.02.2026 19:48:35
Gogs is an open source self-hosted Git service. In versions 0.13.4 and below, the DeleteComment API does not verify that the comment belongs to the repository specified in the URL. This allows a repository administrator to delete comments from any ot...