TechBooky AI Assistant
TechBooky AI Assistant
👋 Welcome to TechBooky AI Assistant

I can help with:
🔎 Tech News
🤖 AI Topics
💻 Gadgets
☁️ Cloud
✍️ Guest Posts
📢 Advertising
🔗 Backlinks
📩 Newsletter
  • AI Search
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise Here
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Enterprise

Gogs Fixes Critical Zero-Day Bug That Enabled Remote Code Execution

Akinola Ajibola by Akinola Ajibola
June 8, 2026
in Enterprise
Share on FacebookShare on Twitter

A serious security zero-day vulnerability that may give hackers privilege and access to any repository (including private ones) and compromise Internet-facing instances has been fixed by Gogs.

This is to address a zero-day argument injection vulnerability that enables authenticated users to accomplish Remote Code Execution (RCE) and completely compromise susceptible servers, Gogs has released crucial security fixes.

All Gogs releases up to and including 0.14.2 and 0.15.0+dev are affected by this argument injection vulnerability, which has not yet been given a CVE ID and can only be allowed to be used by authenticated attackers without admin rights.

Jonah Burgess, a security researcher at Rapid7, found the vulnerability, which has a CVSSv4 score of 9.4 and affects the default configurations of the widely used self-hosted Git service.

By taking advantage of this vulnerability, they have an opportunity to gain access to the targeted server, read any repository, including private repositories, steal passwords, travel laterally to other networked computers, and change any stored source code.

This weakness had affected all Gogs servers with default setups, according to Rapid7 security researcher Jonah Burgess, who found and reported it, even though threat actors would require at least basic user privileges to exploit it.

Around two weeks ago, there was a warning issued by Burgess that stated that an unauthenticated attacker can simply create an account and repository on any default-configured instance because Gogs ships with open registration enabled by default (DISABLE_REGISTRATION = false) and no limit on repository creation (MAX_CREATION_LIMIT = -1). It went further to say that any registered user who creates a repository is automatically its owner. After that, all it takes is a single settings toggle to enable rebase merging, and the entire exploit chain may be managed without the involvement of any other user.

The Gogs maintainers issued version 0.14.3 yesterday to fix this vulnerability and requested a CVE ID over the weekend, ten days after the cybersecurity company publicly revealed it due to a lack of response to several status updates.

Based on Rapid7, all Gogs users should upgrade right away, according to Rapid7. Burgess had said that Pull request #8301 was used to implement the patch.

For users who are unable to fix their Gogs instances right now, Rapid7 provides preventive strategies that call for them to:

  • Limit user registration by setting DISABLE_REGISTRATION = true in app.ini to stop unauthorized users from registering. Given that the exploit is self-contained within the repository of a single user, this prevention means it has the most impact.
  • Limit repository creation (MAX_CREATION_LIMIT = 0 in app.ini) to stop users from making their own repositories. Through the admin panel’s Max Repo Creation feature, this can also be customized per single user. This prevents people with write access to existing repositories from exploiting it, but it does stop the simplest attack path by creating a new repository with rebase enabled.
  • Audit rebase merge settings: Although “Rebase before merging” can be turned off per repo under Settings > Advanced, users should keep in mind that a malicious user who owns or has admin access to a repository can re-enable rebase at any time, and this is not a reliable safeguard.

Gogs, a Go program created as a substitute for GitHub Enterprise or GitLab, is frequently used online as a platform for remote collaboration.

While Shodan identifies little more than 1,000 IP addresses with a Gogs fingerprint, internet security watchdog Shadowserver presently monitors approximately 2,300 Internet-exposed Gogs servers, the majority of which are in Asia (1,839) and Europe (312).

Burgess added that although the weakness affects a different code path (Merge()), it is remarkably similar to other argument-injection flaws that the Gogs security team has corrected in recent years (such as CVE-2024-39933, CVE-2024-39932, CVE-2026-26194, and CVE-2024-39930).

Another RCE vulnerability (CVE-2025-8110) was patched by Gogs in early December 2026 after it was used in zero-day attacks to compromise hundreds of servers. “Many of these instances are configured with ‘Open Registration’ enabled by default, creating a massive attack surface,” according to Wiz security researchers who reported the flaw.

CISA added CVE-2025-8110 to its list of regularly exploited vulnerabilities on January 12 after confirming that it was being misused in the wild. Federal Civilian Executive Branch (FCEB) entities were then instructed to secure their servers within three weeks, by February 2.

CISA, at a time, warned that this type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.

For urgent remediation steps, for anyone operating an internet-facing or internal Gogs instance, take the following defensive actions immediately:

  • Update Immediately: Apply the latest security patches from the Gogs development team to secure your Merge() code paths.
  • Disable Open Registration: If you cannot update right away, modify your configuration file to block unknown users from creating accounts.

  • Restrict Repo Creation: Enforce strict limits so that only authorized administrators or vetted accounts can create new repositories.
  • Remove Internet Exposure: Place your Git infrastructure behind a secure VPN or internal network instead of exposing it directly via public IP addresses.

Related Posts:

  • microsofts-surface-duo-dualscreen-androi-5f1f3d057e8c350ae07dd862-1-jul-28-2020-15-24-20-poster
    Microsoft Patch Tuesday Fixes 63 Bugs, 1 Zero-Day
  • Cloudflare-AI_Bot-Blocking
    Cloudflare Blames React2Shell Protections for Outage
  • 1_8_VsolmlGbZ-OhZN0wEgrw
    Over 46,000 Grafana Instances Vulnerable to Account Takeover
  • Microsoft SharePoint CTA
    Microsoft Warns of Critical SharePoint Zero-day…
  • 4025691-0-97050800-1753099410-original
    Microsoft Patches SharePoint Bug, Leaves 2016…
  • was-ist-cpanel
    Hackers Are Exploiting Critical cPanel Bug, Putting…
  • sharepoint-stock-image
    Hackers Team Up to Attack Microsoft SharePoint Systems
  • microsoft-sharepoint-104_v-variantBig1x1_w-1280_zc-3061602c
    SharePoint Zero-day Persists Despite Microsoft Patches

Discover more from TechBooky

Subscribe to get the latest posts sent to your email.

Tags: GogsZero-day vulnerabilities
Akinola Ajibola

Akinola Ajibola

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • Gogs Fixes Critical Zero-Day Bug That Enabled Remote Code Execution June 8, 2026
  • Amazon Adds AI-Powered Custom Merch Design June 8, 2026
  • NDPC & Meta Roll Out 2-Year Data Protection Program June 8, 2026
  • FCCPC Deregulates Airtime Lending in Nigeria June 6, 2026
  • Interswitch Jumps Into Africa’s Banking Tech Race With Temenos Deal June 6, 2026
  • Record Labels Face Lawsuit From Musicians’ Union Over AI Licensing June 6, 2026
  • Whistleblower Accuses IBM of Hiding Data Breaches June 6, 2026
  • Google Agrees To Pay SpaceX $920M Monthly For Cloud Compute Capacity June 6, 2026
  • New Malware Deployed By Chinese APT To Retain Access To Hacked Systems June 6, 2026
  • Google Chrome Tests Direct-to-AI Mode Search June 6, 2026
  • OpenAI Adds New Memory System to Make ChatGPT More Context-Aware June 5, 2026
  • Google Adds Search Profiles For Publishers & Creators June 5, 2026

Browse Archives

June 2026
MTWTFSS
1234567
891011121314
15161718192021
22232425262728
2930 
« May    

Quick Links

  • About TechBooky
  • Advertise Here
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • AI Search
  • About TechBooky
  • Advertise Here
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.