Skip to content

CVE-2025-8110

CVE

Threat entity extracted from intelligence sources

Frequency
17
occurrences
First Seen
December 10, 2025
Last Seen
May 28, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated that government agencies secure their systems against a critical Gogs vulnerability, tracked as CVE-2025-8110. This remote code execution (RCE) flaw, stemming from a path traversal weakness in the PutContents API, has been...

A zero-day vulnerability in Gogs, identified as CVE-2025-8110, is being actively exploited, allowing authenticated users to execute remote code. This flaw affects over 50% of public-facing Gogs instances, and as of now, no patch is available to mitigate the issue.

A critical argument injection vulnerability (CWE-88) has been discovered in Gogs, a widely used self-hosted Git service, allowing authenticated users to execute arbitrary code on the server. The flaw, identified by Rapid7's Jonah Burgess, has a CVSSv4 score of 9.4 and affects Gogs versions 0.14.2 an...

A zero-day vulnerability in Gogs, a self-hosted Git service, is being actively exploited, affecting over 700 instances. Discovered by Wiz Research during a malware investigation, the vulnerability allows authenticated users to execute remote code by overwriting files outside the repository. As of De...

Public Exploits

Checking GitHub for proof-of-concept code…

Related Articles (17)

1 / 4