Sploitus

CVE-2026-25921

No indexed exploits for CVE-2026-25921 yet

Gogs is an open source self-hosted Git service. Prior to version 0.14.2, overwritable LFS object across different repos leads to supply-chain attack, all LFS objects are vulnerable to be maliciously overwritten by malicious attackers. This issue has been patched in version 0.14.2.

Affected products
Gogs
Gogs
< 0.14.2
Fix
Available
CVSS 3.1
9.3 CRITICAL
EPSS
0.3% (25th percentile)
Weakness
CWE-345
NVD status
Analyzed
Published
2026-03-05
CVE-2026-25921 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-25921 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-25921 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.