• AI Search
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise With TechBooky
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Enterprise

Gogs Fixes Critical Zero-Day Bug That Enabled Remote Code Execution

Akinola Ajibola by Akinola Ajibola
June 8, 2026
in Enterprise
Share on FacebookShare on Twitter
In Brief
  • A serious security zero-day vulnerability that may give hackers privilege and access to any repository (including private ones) and compromise Internet-facing instances has been fixed by...
  • This is to address a zero-day argument injection vulnerability that enables authenticated users to accomplish Remote Code Execution (RCE) and completely compromise susceptible servers, Gogs has...
  • All Gogs releases up to and including 0.14.2 and 0.15.0+dev are affected by this argument injection vulnerability, which has not yet been given a CVE ID...

A serious security zero-day vulnerability that may give hackers privilege and access to any repository (including private ones) and compromise Internet-facing instances has been fixed by Gogs.

This is to address a zero-day argument injection vulnerability that enables authenticated users to accomplish Remote Code Execution (RCE) and completely compromise susceptible servers, Gogs has released crucial security fixes.

All Gogs releases up to and including 0.14.2 and 0.15.0+dev are affected by this argument injection vulnerability, which has not yet been given a CVE ID and can only be allowed to be used by authenticated attackers without admin rights.

Jonah Burgess, a security researcher at Rapid7, found the vulnerability, which has a CVSSv4 score of 9.4 and affects the default configurations of the widely used self-hosted Git service.

By taking advantage of this vulnerability, they have an opportunity to gain access to the targeted server, read any repository, including private repositories, steal passwords, travel laterally to other networked computers, and change any stored source code.

This weakness had affected all Gogs servers with default setups, according to Rapid7 security researcher Jonah Burgess, who found and reported it, even though threat actors would require at least basic user privileges to exploit it.

Around two weeks ago, there was a warning issued by Burgess that stated that an unauthenticated attacker can simply create an account and repository on any default-configured instance because Gogs ships with open registration enabled by default (DISABLE_REGISTRATION = false) and no limit on repository creation (MAX_CREATION_LIMIT = -1). It went further to say that any registered user who creates a repository is automatically its owner. After that, all it takes is a single settings toggle to enable rebase merging, and the entire exploit chain may be managed without the involvement of any other user.

The Gogs maintainers issued version 0.14.3 yesterday to fix this vulnerability and requested a CVE ID over the weekend, ten days after the cybersecurity company publicly revealed it due to a lack of response to several status updates.

Based on Rapid7, all Gogs users should upgrade right away, according to Rapid7. Burgess had said that Pull request #8301 was used to implement the patch.

For users who are unable to fix their Gogs instances right now, Rapid7 provides preventive strategies that call for them to:

  • Limit user registration by setting DISABLE_REGISTRATION = true in app.ini to stop unauthorized users from registering. Given that the exploit is self-contained within the repository of a single user, this prevention means it has the most impact.
  • Limit repository creation (MAX_CREATION_LIMIT = 0 in app.ini) to stop users from making their own repositories. Through the admin panel’s Max Repo Creation feature, this can also be customized per single user. This prevents people with write access to existing repositories from exploiting it, but it does stop the simplest attack path by creating a new repository with rebase enabled.
  • Audit rebase merge settings: Although “Rebase before merging” can be turned off per repo under Settings > Advanced, users should keep in mind that a malicious user who owns or has admin access to a repository can re-enable rebase at any time, and this is not a reliable safeguard.

Gogs, a Go program created as a substitute for GitHub Enterprise or GitLab, is frequently used online as a platform for remote collaboration.

While Shodan identifies little more than 1,000 IP addresses with a Gogs fingerprint, internet security watchdog Shadowserver presently monitors approximately 2,300 Internet-exposed Gogs servers, the majority of which are in Asia (1,839) and Europe (312).

Burgess added that although the weakness affects a different code path (Merge()), it is remarkably similar to other argument-injection flaws that the Gogs security team has corrected in recent years (such as CVE-2024-39933, CVE-2024-39932, CVE-2026-26194, and CVE-2024-39930).

Another RCE vulnerability (CVE-2025-8110) was patched by Gogs in early December 2026 after it was used in zero-day attacks to compromise hundreds of servers. “Many of these instances are configured with ‘Open Registration’ enabled by default, creating a massive attack surface,” according to Wiz security researchers who reported the flaw.

CISA added CVE-2025-8110 to its list of regularly exploited vulnerabilities on January 12 after confirming that it was being misused in the wild. Federal Civilian Executive Branch (FCEB) entities were then instructed to secure their servers within three weeks, by February 2.

CISA, at a time, warned that this type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.

For urgent remediation steps, for anyone operating an internet-facing or internal Gogs instance, take the following defensive actions immediately:

  • Update Immediately: Apply the latest security patches from the Gogs development team to secure your Merge() code paths.
  • Disable Open Registration: If you cannot update right away, modify your configuration file to block unknown users from creating accounts.

  • Restrict Repo Creation: Enforce strict limits so that only authorized administrators or vetted accounts can create new repositories.
  • Remove Internet Exposure: Place your Git infrastructure behind a secure VPN or internal network instead of exposing it directly via public IP addresses.

Related Reading

Explore more TechBooky stories from the latest and category sections below.

Keep Reading Smarter

Search TechBooky with AI

Use TechBooky's AI Search to explore the context behind this story and related coverage across the site.

Try AI Search
More On This Topic
Enterprise

Discover more from TechBooky

Subscribe to get the latest posts sent to your email.

Tags: GogsZero-day vulnerabilities
Akinola Ajibola

Akinola Ajibola

Search TechBooky
Open TechBooky AI Search Try the AI Assistant

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • Paystack’s AI Checkout Experiment Could Change How Nigerians Pay Online July 13, 2026
  • Apple’s OpenAI Lawsuit Turns The AI Hardware Race Into A Legal Fight July 13, 2026
  • Sam Altman And Elon Musk Are Now Fighting Over Space Data Centres July 13, 2026
  • Flutterwave’s Circle Ventures Investment Pushes Stablecoin Payments Deeper Into Africa July 12, 2026
  • Nigeria’s Probe Into Meta, X, Alphabet And AI Firms Puts Big Tech’s Media Power On Trial July 12, 2026
  • AI Spending Is Starting To Look Like An Inflation Story, Not Just A Tech Story July 12, 2026
  • OpenAI’s Fidji Simo Steps Down From AGI Deployment Role, Citing Health Challenges July 10, 2026
  • CBN’s Data Localisation Directive Puts Nigerian Fintechs In A Cloud Dilemma July 10, 2026
  • Europe’s AI Boom Is Finally Here and Investors Can’t Get Enough July 9, 2026
  • OpenAI’s GPT-5.6 Sol Shows AI Is Now Treated Like Critical Infrastructure July 9, 2026
  • Meta Is No Longer Giving AI Away for Free. It’s Coming for OpenAI’s Business. July 9, 2026
  • Slack Ties Slackbot Directly Into Salesforce Data And Apps Via Model Context Protocol July 9, 2026

Browse Archives

July 2026
M T W T F S S
 12345
6789101112
13141516171819
20212223242526
2728293031  
« Jun    

Quick Links

  • About TechBooky
  • Advertise With TechBooky
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • AI Search
  • About TechBooky
  • Advertise With TechBooky
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.