logo

Gogs patches critical zero-day enabling remote code execution

ID: 5a9adaf9-d728-5656-9d67-aa4a36b900cf

STIX ID: report--5a9adaf9-d728-5656-9d67-aa4a36b900cf

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-06-08

Date Updated: 2026-06-08

Author: Sergiu Gatlan

...
...

Rapid7 disclosed a critical argument-injection zero-day in Gogs that can be exploited by users (easy to obtain on default installs with open registration) to compromise servers, read or modify any repositories including private ones, and move laterally; Gogs issued patch 0.14.3 and recommended mitigations (disable registration, limit repo creation, audit rebase merge settings), while thousands of Gogs instances remain Internet-exposed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.