https://seclists.org/oss-sec/2025/q4/262: CVE-2025-8110 in Gogs self-hosted git service
Published Dec 10, 2025
·Updated
Affected Software
1 affected component
github/gogs
Frequently Asked Questions
1
What is the severity of CVE-2025-8110?
CVE-2025-8110 is a critical vulnerability that has been actively exploited in the wild.
2
How do I fix CVE-2025-8110?
Currently, there is no official patch available for CVE-2025-8110, so users should apply mitigation strategies such as restricting access or disabling vulnerable features.
3
What type of vulnerability is CVE-2025-8110?
CVE-2025-8110 is classified as a remote code execution (RCE) vulnerability.
4
Who is affected by CVE-2025-8110?
Any users of the Gogs self-hosted git service are potentially affected by CVE-2025-8110.
5
What are the potential consequences of CVE-2025-8110?
Exploitation of CVE-2025-8110 could allow an attacker to execute arbitrary code on the affected server.