https://seclists.org/oss-sec/2026/q1/87: CVE-2025-8110 in Gogs self-hosted git service
Published Jan 18, 2026
·Updated
Affected Software
1 affected component
gogs/gogs
CVE-2025-8110 is rated as a medium severity vulnerability.
CVE-2025-8110 is classified as a Time-of-Check to Time-of-Use (TOCTOU) race condition.
To fix CVE-2025-8110, ensure that proper checks are implemented before creating directories to prevent symbolic link attacks.
CVE-2025-8110 affects the Gogs self-hosted git service.
CVE-2025-8110 was published on January 18, 2026.