PT-2026-23487 · Gogs · Gogs

Rezmoss

·

Published

2026-02-13

·

Updated

2026-03-25

·

CVE-2026-26196

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Gogs versions prior to 0.14.2
Description The Gogs API accepts tokens in URL parameters, specifically token and access token. This can lead to information disclosure as these tokens may be logged, stored in browser history, or sent in referrer headers. The API checks for tokens in URL query parameters before checking the Authorization header. Token-authenticated requests are accepted by API routes. This allows for potential reuse of tokens until they are revoked.
Recommendations Versions prior to 0.14.2 should be updated to version 0.14.2. Authentication headers should be used exclusively for token transmission. Token parameters should be blocked at the proxy or WAF level. Query strings should be scrubbed from logs. A strict referrer policy should be set.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-06148
CVE-2026-26196
GHSA-X9P5-W45C-7FFC
GO-2026-4619
SUSE-SU-2026:1042-1

Affected Products

Gogs