📰 Unpatched Critical RCE Flaw (CVSS 9.4) in Gogs Git Service Puts Repositories at Risk

🚨 URGENT: A critical 9.4 CVSS unpatched RCE vulnerability has been disclosed in the Gogs Git service. Default installations are at risk of complete server takeover. No patch is available. Restrict access immediately! ⚠️ #Gogs #RCE #Vulnerability #Gi...

🌐 cyber[.]netsecops[.]io

🔗 https://cyber.netsecops.io/articles/critical-unpatched-rce-flaw-disclosed-in-gogs-git-service/?utm_sou…

Warten auf Sicherheitspatch: Self-hosted-Git-Service #Gogs ist verwundbar | Security https://www.heise.de/news/Warten-auf-Sicherheitspatch-Self-hosted-Git-Service-Gogs-ist-verwundbar-11311027.html #git 
Warten auf Sicherheitspatch: Self-hosted-Git-Service Gogs ist verwundbar

Angreifer können Gogs-Server in den Standardeinstellungen mit Schadcode attackieren. Bislang können Admins Systeme nur über einen Workaround schützen.

heise online
New Gogs zero-day flaw lets hackers get remote code execution

An unpatched zero-day vulnerability in the Gogs self-hosted Git service can allow attackers to gain remote code execution (RCE) on Internet-facing instances.

BleepingComputer

Gogs Vulnerability Exposes Open-Source Git Service to RCE Attacks

A critical vulnerability in Gogs, an open-source Git service, has been exposed, leaving users open to remote code execution (RCE) attacks - and an exploit module is already available. The flaw was reported as early as March, but shockingly, the project's maintainers have failed to respond to the researcher ever since.

https://osintsights.com/gogs-vulnerability-exposes-open-source-git-service-to-rce-attacks?utm_source=mastodon&utm_medium=social

#Gogs #RemoteCodeExecution #Rce #Opensource #Git

Gogs Vulnerability Exposes Open-Source Git Service to RCE Attacks

Learn about the critical RCE vulnerability in Gogs, an open-source Git service, and take immediate action to secure your instance with our expert guidance now.

OSINTSights

Gogs Vulnerability Exposes Remote Code Execution Risk

A newly discovered vulnerability in Gogs puts servers at risk of remote code execution, allowing any authenticated user to inject malicious code through a simple pull request. By crafting a malicious branch name, attackers can exploit the --exec flag in git rebase to run unauthorized shell commands.

https://osintsights.com/gogs-vulnerability-exposes-remote-code-execution-risk?utm_source=mastodon&utm_medium=social

#RemoteCodeExecution #Gogs #Vulnerability #Git #SupplyChain

Gogs Vulnerability Exposes Remote Code Execution Risk

Learn how Gogs vulnerability enables remote code execution via malicious branch names and take immediate action to secure your server now effectively.

OSINTSights

Gogs users, beware: A new zero-day (CVE-2025-8110) is actively being exploited, allowing authenticated attackers to achieve remote code execution. This flaw, discovered by Wiz Research, bypasses a previous fix by abusing symbolic link handling, with CISA mandating federal agencies to mitigate by Feb 2, 2026. Over 700 instances are already compromised, yet an official patch remains unavailable.

https://www.tpp.blog/2o9i6js

#cybersecurity #gogs #wizresearch

🤖 This post was AI-generated.

Gogs Zero-Day Flaw Enables Remote Code Execution on Exposed Servers

A zero-day flaw in Gogs, a self-hosted Git service, leaves exposed servers vulnerable to remote code execution - and it's surprisingly easy for attackers to exploit, as they can create an account and repository on default-configured instances. This critical-severity vulnerability affects the latest release versions and…

https://osintsights.com/gogs-zero-day-flaw-enables-remote-code-execution-on-exposed-servers?utm_source=mastodon&utm_medium=social

#Gogs #ZeroDay #RemoteCodeExecution #ArgumentinjectionFlaw #SelfhostedGitService

Gogs Zero-Day Flaw Enables Remote Code Execution on Exposed Servers

Learn about the Gogs zero-day flaw that enables remote code execution on exposed servers and take immediate action to secure your instance now with our expert guidance.

OSINTSights
Ok. Nach der Entwicklung bei #gitlab sehe ich mich nach Alternativen um. #onedev fällt aus: "Built-in AI for DevOps Intelligence" und "Workspaces for Vibe Coding" - würg! #gogs genauso: ich klicke auf der Startseite auf "features" und lande mitten in der Doku unter "authentication" - brauch ich nicht! #radicle hatte ich mir schon mal angesehen und fand's damals zu kompliziert und sinnlos - neues Protokoll, das alles tut, was #git tut - es nur anders nennt - nee... #gitea - hmm, weiß ich nicht..
@adele I have an account on #Codeberg but I also have #Gogs on my homelab and #Forgejo on one of the dedicated servers. Mainly to synchronize data that is important to me
How to setup a self-hosted #git server at home using just #cli and #ssh, without using #gitea or #gogs , so you can migrate your personal projects away from #Bitbucket or #github or #gitlab https://vikaskumar.org/2026/05/01/setup-self-hosted-git-server.html
SETUP SELF-HOSTED GIT SERVER ON LINUX

With the enshittification of Github and potentially, Bitbucket with AI tools and changes in terms of services where the owners of those platforms could decide to start training ...