2026 CVE Vulnerabilities

60,152 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-52811CRITICAL9Gogs is an open source self-hosted Git service. Prior to 0.14.3, (*Repository).UploadRepoFiles checks for symlinks only ...
CVE-2026-52810HIGH7.1Gogs is an open source self-hosted Git service. Prior to 0.14.3, Git smart HTTP authorizes POST …/git-receive-pack using...
CVE-2026-52809MEDIUM6.8Gogs is an open source self-hosted Git service. Prior to 0.14.3, password-reset tokens are generated using conf.Auth.Act...
CVE-2026-52808HIGH7.1Gogs is an open source self-hosted Git service. Prior to 0.14.3, three API endpoints — PATCH /api/v1/repos/:owner/:repo/...
CVE-2026-52807MEDIUM4.8Gogs is an open source self-hosted Git service. Prior to 0.14.3, in new_form.tmpl, milestone names are rendered with Go'...
CVE-2026-52806CRITICAL9.9Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code ...
CVE-2026-52805HIGH8.7Gogs is an open source self-hosted Git service. Prior to 0.14.3, a Server-Side Request Forgery (SSRF) vulnerability exis...
CVE-2026-52804MEDIUM5.5Gogs is an open source self-hosted Git service. Prior to 0.14.3, a repository admin collaborator can escalate their priv...
CVE-2026-52802MEDIUM5.4Gogs is an open source self-hosted Git service. Prior to 0.14.3, an open redirect vulnerability exists in Gogs where att...
CVE-2026-52801HIGH8.1Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Gogs Mirror Settings functionality provide an alter...
CVE-2026-52800HIGH8.8Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization team member management can be performed vi...
CVE-2026-52799HIGH7.5Gogs is an open source self-hosted Git service. Prior to 0.14.3, GET /attachments/:uuid returns the raw attachment file ...
CVE-2026-52798HIGH8.9Gogs is an open source self-hosted Git service. Prior to 0.14.3, although .ipynb previews are sanitized on the server si...
CVE-2026-52797HIGH8.5Gogs is an open source self-hosted Git service. Prior to 0.14.0, as an authorized user, an intruder can dictate the valu...
CVE-2026-52796LOW3.5Gogs is an open source self-hosted Git service. Prior to 0.14.3, specially crafted issue index pattern can cause a panic...
CVE-2026-52795MEDIUM4.3Gogs is an open source self-hosted Git service. In 0.14.3 and earlier, any authenticated user can watch a private reposi...
CVE-2026-50129HIGH7.5Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.11, 4.4.18, and 4.3.24, a DoS c...
CVE-2026-50128MEDIUM5.3Mastodon is a free, open-source social network server based on ActivityPub. From 4.3.0 until 4.5.11 and 4.4.18, Mastodon...
CVE-2026-49278MEDIUM6.7Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, ...
CVE-2026-49277LOW2.3Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, ...
CVE-2026-47733MEDIUM4.4Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, the ImageElement comp...
CVE-2026-47267HIGH8.3Gogs is an open source self-hosted Git service. Prior to 0.14.3, the fix for CVE-2022-1285 prevents adding webooks or ru...
CVE-2026-46423CRITICAL9.3Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, ...
CVE-2026-45757LOW2.3Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, ...
CVE-2026-45689CRITICAL9.1Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now