All verified exploits

CVE-2026-25921 LFS Supply-Chain Object Overwrite

Deterministic critical Gogs Added cve-verified-cve-2026-25921

Detects vulnerable Gogs versions where LFS object uploads lack SHA256 content hash verification, allowing cross-repository object overwrite and supply-chain poisoning.

Is your app exploitable through CVE-2026-25921?

Scan your domain free