logo

How to find Gogs installations on your network

ID: 7ff6bc57-8589-544e-b0a2-6705c4d6dac0

STIX ID: report--7ff6bc57-8589-544e-b0a2-6705c4d6dac0

Feed Name: runZero Blog

Threat Score
74/100

Date Published: 2025-12-10

Date Updated: 2026-04-29

Author: Rob King

...
...

**CVE-2025-8110 (Gogs RCE) —** A 0-day remote-authenticated vulnerability in Gogs (affecting versions 0.13.3 and prior) enables arbitrary file overwrite and remote code execution with the Gogs server process privileges; it has a CVSS score of 7.8, is reported to be actively exploited in the wild, no fixed release is available, and mitigations include disabling auto-registration and avoiding Internet exposure; a runZero query (favicon MD5) is provided to discover likely vulnerable hosts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.