Critical Vulnerabilities in Gogs and Jinjava Require Immediate Patching

Critical Vulnerabilities in Gogs and Jinjava Require Immediate Patching

First seen 25 Jun 2026, 20:01 UTC Mallory.AiCcb.Belgium.Besecurityonline.info 87% similarity 72.0
Share:

Article Content

Browse articles
ThreatCluster

Multiple critical vulnerabilities affecting Gogs and Jinjava have been disclosed, with severe impacts including remote code execution (RCE) and unauthorized file access. Gogs vulnerabilities include CVE-2025-64111 (RCE), CVE-2025-64175 (2FA bypass), and CVE-2026-24135 (path traversal), all affecting versions prior to 0.14.3. Jinjava's CVE-2026-25526 allows arbitrary Java code execution through a sandbox escape. The vulnerabilities can lead to full host takeover and theft of sensitive data. Administrators are urged to upgrade to patched versions immediately. Active exploitation has been reported for other vulnerabilities in related systems. The Centre for Cybersecurity Belgium emphasizes the urgency of patching to prevent potential breaches.

Key Points: • Gogs has multiple critical vulnerabilities allowing remote code execution and file manipulation. • Jinjava's vulnerability enables arbitrary Java code execution through a sandbox escape. • Immediate patching is recommended to mitigate risks of exploitation and data theft.

ThreatCluster AI

Timeline

2026-01-29
CVE-2026-1281 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-01-29
CVE-2026-1340 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-02-04
CVE-2026-25526 published
Jinjava disclosed a critical vulnerability allowing arbitrary Java code execution.
Mallory.Ai
2026-02-06
CVE-2025-64111, CVE-2025-64175, CVE-2026-24135 published
Gogs disclosed multiple vulnerabilities enabling RCE and account takeover.
Mallory.Ai
2026-02-12
Public exploit for CVE-2025-62878 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2026-06-24
CVE-2026-52813, CVE-2026-52806 published
New Gogs vulnerabilities disclosed, allowing RCE and unauthorized file writes.
Ccb.Belgium.Be
2026-06-24
CVE-2026-52811 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-25
Patching recommended
Centre for Cybersecurity Belgium advises immediate patching of Gogs installations to mitigate risks.
Ccb.Belgium.Be

Community

Browse all →