Three critical Gitea and Gogs CVEs disclosed in 2026: a CVSS 9.8 auth bypass via X-WEBAUTH-USER header, a stored DOM XSS through Semantic UI’s preserveHTML, and an incomplete SSRF fix exposing AWS IMDS credentials
Copy and paste this URL into your WordPress site to embed
Copy and paste this code into your site to embed