https://seclists.org/oss-sec/2026/q1/86: CVE-2025-8110 in Gogs self-hosted git service
Published Jan 17, 2026
·Updated
Affected Software
1 affected component
github/gogs
CVE-2025-8110 is reported to have a high severity level due to its potential for remote code execution.
As of now, there is no official patch available for CVE-2025-8110, but users are advised to monitor Gogs' official communications for updates.
CVE-2025-8110 affects instances of the Gogs self-hosted git service.
The vulnerability could allow attackers to execute arbitrary code on the server hosting Gogs.
Yes, there have been reports indicating that CVE-2025-8110 is being actively targeted by attackers.