๐Ÿ” CVE Alert

CVE-2026-26196

UNKNOWN 0.0

Gogs: Access tokens get exposed through URL params in API requests

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Gogs is an open source self-hosted Git service. Prior to version 0.14.2, gogs api still accepts tokens in url params like token and access_token, which can leak through logs, browser history, and referrers. This issue has been patched in version 0.14.2.

CWE CWE-598
Vendor gogs
Product gogs
Published Mar 5, 2026
Last Updated Mar 6, 2026
Stay Ahead of the Next One

Get instant alerts for gogs gogs

Be the first to know when new unknown vulnerabilities affecting gogs gogs are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

gogs / gogs
< 0.14.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/gogs/gogs/security/advisories/GHSA-x9p5-w45c-7ffc github.com: https://github.com/gogs/gogs/pull/8177 github.com: https://github.com/gogs/gogs/commit/295bfba72993c372e7b338438947d8e1a6bed8fd github.com: https://github.com/gogs/gogs/releases/tag/v0.14.2