INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Gogs Patches Critical Zero-Day Flaw Enabling Remote Code Execution
| 2026-06-08 16:18 CRITICAL MEDIUM EXPLOITED VULNERABILITY VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
On June 8, 2026, a critical zero-day vulnerability was discovered in Gogs, allowing authenticated attackers without admin privileges to exploit an argument injection flaw that affects all releases up to and including version 0.14.2 and 0.15.0+dev. The vulnerability can be exploited by creating a new repository with rebase enabled, which is not effectively defended against by disabling "Rebase before merging" per-repo under Settings > Advanced due to malicious users having admin access or owning the repo. Gogs maintainers released version 0.14.3 on June 7 to patch this flaw and Rapid7 recommends immediate upgrade for all users; mitigation measures include restricting user registration and repository creation, which can be set via [IOC HIDDEN • LOGIN REQUIRED] files.
Technical Mitigations AI-generated
• Restrict user registration (DISABLE_REGISTRATION = true in <a href="/auth/login?next=/detail/frNEcp4BHUyMcQl6C0Bw" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN • LOGIN REQUIRED]</span></a>) to prevent untrusted users from creating accounts.
• Restrict repository creation (MAX_CREATION_LIMIT = 0 in <a href="/auth/login?next=/detail/frNEcp4BHUyMcQl6C0Bw" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN • LOGIN REQUIRED]</span></a>) to prevent users from creating their own repos.
• Audit rebase merge settings: Disable "Rebase before merging" per-repo under Settings > Advanced.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
ap•••••.ini
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2024-39930CVE-2024-39930
CVE-2024-39933CVE-2024-39933
CVE-2024-39932CVE-2024-39932
CVE-2026-26194CVE-2026-26194
CVE-2025-8110CVE-2025-8110
Target & Sectors
EUROPE
EUROPE
Incident Timeline
2026/06/08
Threat actors exploited a previously unpatched zero-day vulnerability in Gogs, allowing authenticated attackers without admin privileges to gain remote code execution.
Click on any entity below to view its context and source!
infrastructure
0.14.2
This
argument injection
vulnerability has yet to be assigned a CVE ID, can only be exploited by authenticated attackers without admin privileges, and affects all Gogs releases up to and including 0.14.2 and 0.15.0+dev.
This critical severity
argument injection
security flaw has yet to be assigned a CVE ID, affects the latest release versions (Gogs 0.14.2 and 0.15.0+dev), and can only be exploited by authenticated attackers without admin privileges.
infrastructure
0.15.0
This
argument injection
vulnerability has yet to be assigned a CVE ID, can only be exploited by authenticated attackers without admin privileges, and affects all Gogs releases up to and including 0.14.2 and 0.15.0+dev.
This critical severity
argument injection
security flaw has yet to be assigned a CVE ID, affects the latest release versions (Gogs 0.14.2 and 0.15.0+dev), and can only be exploited by authenticated attackers without admin privileges.
infrastructure
0.14.3
"
Over the weekend, 10 days after the cybersecurity company publicly disclosed it following a lack of response to multiple status updates, the Gogs maintainers released
version 0.14.3 on June 7
to patch this flaw and requested a CVE ID.
infrastructure
2,300 exposed Gogs servers
Internet security watchdog Shadowserver currently tracks
over 2,300 Internet-exposed Gogs servers
, most of them in Asia (1,839) and Europe (312), while Shodan lists
just over 1,000 IP addresses
with a Gogs fingerprint.
financial
312 Europe
Internet security watchdog Shadowserver currently tracks
over 2,300 Internet-exposed Gogs servers
, most of them in Asia (1,839) and Europe (312), while Shodan lists
just over 1,000 IP addresses
with a Gogs fingerprint.
infrastructure
1,000 IP addresses
Internet security watchdog Shadowserver currently tracks
over 2,300 Internet-exposed Gogs servers
, most of them in Asia (1,839) and Europe (312), while Shodan lists
just over 1,000 IP addresses
with a Gogs fingerprint.
Internet security watchdog Shadowserver now tracks
over 2,400 Gogs servers
exposed online, most of them in Asia (1,894) and Europe (319), while Shodan found
just over 1,000 IP addresses
with a Gogs fingerprint.
infrastructure
2,400 Gogs servers
Internet security watchdog Shadowserver now tracks
over 2,400 Gogs servers
exposed online, most of them in Asia (1,894) and Europe (319), while Shodan found
just over 1,000 IP addresses
with a Gogs fingerprint.
financial
319 Europe
Internet security watchdog Shadowserver now tracks
over 2,400 Gogs servers
exposed online, most of them in Asia (1,894) and Europe (319), while Shodan found
just over 1,000 IP addresses
with a Gogs fingerprint.
financial
8301 request
The fix was implemented via
pull request #8301
," Burgess added.
Tactical Metrics
Metrics
infrastructure
0.14.2
Software Version
Click for context!
This
argument injection
vulnerability has yet to be assigned a CVE ID, can only be exploited by authenticated attackers without admin privileges, and affects all Gogs releases up to and including 0.14.2 and 0.15.0+dev.
This critical severity
argument injection
security flaw has yet to be assigned a CVE ID, affects the latest release versions (Gogs 0.14.2 and 0.15.0+dev), and can only be exploited by authenticated attackers without admin privileges.
Metrics
infrastructure
0.15.0
Software Version
This
argument injection
vulnerability has yet to be assigned a CVE ID, can only be exploited by authenticated attackers without admin privileges, and affects all Gogs releases up to and including 0.14.2 and 0.15.0+dev.
This critical severity
argument injection
security flaw has yet to be assigned a CVE ID, affects the latest release versions (Gogs 0.14.2 and 0.15.0+dev), and can only be exploited by authenticated attackers without admin privileges.
Metrics
infrastructure
0.14.3
Software Version
"
Over the weekend, 10 days after the cybersecurity company publicly disclosed it following a lack of response to multiple status updates, the Gogs maintainers released
version 0.14.3 on June 7
to patch this flaw and requested a CVE ID.
Metrics
infrastructure
2,300
Exposed Gogs Servers
Internet security watchdog Shadowserver currently tracks
over 2,300 Internet-exposed Gogs servers
, most of them in Asia (1,839) and Europe (312), while Shodan lists
just over 1,000 IP addresses
with a Gogs fingerprint.
Metrics
financial
312
Europe
Internet security watchdog Shadowserver currently tracks
over 2,300 Internet-exposed Gogs servers
, most of them in Asia (1,839) and Europe (312), while Shodan lists
just over 1,000 IP addresses
with a Gogs fingerprint.
Metrics
infrastructure
1,000
Ip Addresses
Internet security watchdog Shadowserver currently tracks
over 2,300 Internet-exposed Gogs servers
, most of them in Asia (1,839) and Europe (312), while Shodan lists
just over 1,000 IP addresses
with a Gogs fingerprint.
Internet security watchdog Shadowserver now tracks
over 2,400 Gogs servers
exposed online, most of them in Asia (1,894) and Europe (319), while Shodan found
just over 1,000 IP addresses
with a Gogs fingerprint.
Metrics
financial
8,301
Request
The fix was implemented via
pull request #8301
," Burgess added.
Metrics
infrastructure
2,400
Gogs Servers
Internet security watchdog Shadowserver now tracks
over 2,400 Gogs servers
exposed online, most of them in Asia (1,894) and Europe (319), while Shodan found
just over 1,000 IP addresses
with a Gogs fingerprint.
Metrics
financial
319
Europe
Internet security watchdog Shadowserver now tracks
over 2,400 Gogs servers
exposed online, most of them in Asia (1,894) and Europe (319), while Shodan found
just over 1,000 IP addresses
with a Gogs fingerprint.
Intelligence Sources
BleepingComputer
2026-05-28
New Gogs zero-day flaw lets hackers get remote code execution
BleepingComputer
BleepingComputer
2026-06-08
Gogs patches critical zero-day enabling remote code execution
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T09:03
Comprehensive Tactical Telemetry
Highly Correlated Entities
16x
organisation
Identified Entity
Gogs
entity
10x
timeline
Temporal Reference
2026/06/18
date
5x
vulnerability
Exploited CVE
CVE-2024-39933
cve
3x
infrastructure
Software Version
0.14.2
version
3x
attribution
Attributing Entity
CVE-2025-8110
authority
2x
general metric
Asia
1,839
asia
2x
financial
Europe
312
europe
2x
general metric
%
54
%
Contextual Telemetry
Context Block
9 METRICS
industry
Targeted Sector
Defense
sector
tactic
Cyber Operation Type
Remote Code Execution
tactic
general metric
Max_Creation_Limit
0
max_creation_limit
target region
Target Region
EUROPE
region
infrastructure
Exposed Gogs Servers
2,300
exposed gogs servers
infrastructure
Ip Addresses
1,000
ip addresses
financial
Request
8,301
request
infrastructure
Gogs Servers
2,400
gogs servers
general metric
Surfaces
6
surfaces
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.