CVE-2026-26195

Gogs is an open source self-hosted Git service. Prior to version 0.14.2, stored xss is still possible through unsafe template rendering that mixes user input with safe plus permissive sanitizer handling of data urls. This issue has been patched in version 0.14.2.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gogs:gogs:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:25

Type Values Removed Values Added
Summary
  • (es) Gogs es un servicio Git autoalojado de código abierto. Antes de la versión 0.14.2, el XSS almacenado sigue siendo posible a través de la renderización insegura de plantillas que mezcla la entrada del usuario con un manejo seguro y permisivo del saneador de las URL de datos. Este problema ha sido parcheado en la versión 0.14.2.

06 Mar 2026, 13:40

Type Values Removed Values Added
References () https://github.com/gogs/gogs/commit/ac21150a53bef3a3061f4da787ab193a8d68ecfc - () https://github.com/gogs/gogs/commit/ac21150a53bef3a3061f4da787ab193a8d68ecfc - Patch
References () https://github.com/gogs/gogs/pull/8176 - () https://github.com/gogs/gogs/pull/8176 - Issue Tracking
References () https://github.com/gogs/gogs/releases/tag/v0.14.2 - () https://github.com/gogs/gogs/releases/tag/v0.14.2 - Release Notes
References () https://github.com/gogs/gogs/security/advisories/GHSA-vgvf-m4fw-938j - () https://github.com/gogs/gogs/security/advisories/GHSA-vgvf-m4fw-938j - Vendor Advisory
First Time Gogs
Gogs gogs
CPE cpe:2.3:a:gogs:gogs:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

05 Mar 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-05 19:16

Updated : 2026-06-17 10:25


NVD link : CVE-2026-26195

Mitre link : CVE-2026-26195

CVE.ORG link : CVE-2026-26195


JSON object : View

Products Affected

gogs

  • gogs
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')