https://seclists.org/oss-sec/2025/q4/262: CVE-2025-8110 in Gogs self-hosted git service
Published Dec 10, 2025
·Updated
Affected Software
1 affected component
github/gogs
CVE-2025-8110 is a critical vulnerability that has been actively exploited in the wild.
Currently, there is no official patch available for CVE-2025-8110, so users should apply mitigation strategies such as restricting access or disabling vulnerable features.
CVE-2025-8110 is classified as a remote code execution (RCE) vulnerability.
Any users of the Gogs self-hosted git service are potentially affected by CVE-2025-8110.
Exploitation of CVE-2025-8110 could allow an attacker to execute arbitrary code on the affected server.