logo

New Gogs zero-day flaw lets hackers get remote code execution

ID: 3f26ef2e-4f5c-5391-a9db-e1729c309abc

STIX ID: report--3f26ef2e-4f5c-5391-a9db-e1729c309abc

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-05-28

Date Updated: 2026-05-28

Author: Sergiu Gatlan

...
...

An unpatched zero-day argument-injection RCE in the Gogs self-hosted Git service (affecting Gogs 0.14.2 and 0.15.0+dev) allows attackers to execute arbitrary code via malicious branch names when rebase-merging; the flaw can be exploited on default-configured, Internet-facing instances because open registration and unlimited repo creation enable attackers to create accounts and repos to trigger the exploit. The researcher reported the issue in March, maintainers have acknowledged but not patched it, and scanners (Shadowserver/Shodan) identify hundreds to thousands of exposed Gogs instances, raising significant risk to hosted repositories, credentials, and servers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.