• News/
  • https://www.theregister.com/2026/01/13/cisa_gogs_exploit/

Federal agencies told to fix or ditch Gogs as exploited zero-day lands on CISA hit list

The Register
·
Carly Page
·
Published Jan 13, 2026
·
Updated

CISA has ordered federal agencies to stop using Gogs or lock it down immediately after a high-severity vulnerability in the self-hosted Git service was added to its Known Exploited Vulnerabilities (KEV) catalog. The US cybersecurity agency added the path traversal flaw to the KEV list on Monday, triggering urgent remediation requirements for federal civilian executive branch (FCEB) agencies. CISA's advisory warns that the vulnerability is being weaponized in attacks, and that agencies should apply mitigations or simply stop using the product if workarounds aren't available. "This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise," CISA said in its alert. The vulnerability, tracked as CVE-2025-8110, was first brought to light by Wiz security researchers in December who stumbled on the unpatched flaw in July while investigating malware on an infected machine. The bug allows authenticated users to bypass protections and overwrite arbitrary files on the host system, effectively granting remote code execution. More than 700 internet-exposed Gogs instances were already confirmed compromised in ongoing attacks at the time of disclosure, with upwards of 1,400 servers found reachable online. Gogs, which is written in Go and allows users to host Git repositories on their own servers or cloud infrastructure, has yet to ship a fix for the flaw, leaving users scrambling for stopgaps such as disabling open reg...

Read full article

Affected Software

1 affected component
Gogs Gogs<all
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a high-severity zero-day vulnerability in the self-hosted Git service Gogs, which has been added to CISA's Known Exploited Vulnerabilities catalog.

2

What security implications are discussed in the article?

Federal agencies are urged to stop using Gogs or implement immediate safeguards due to the potential risks posed by the identified vulnerability.

3

What actions has CISA recommended regarding Gogs?

CISA has recommended that federal agencies either discontinue the use of Gogs or lock it down to prevent exploitation.

4

What type of software is Gogs categorized as?

Gogs is categorized as a self-hosted Git service software.

5

Who is affected by this vulnerability in Gogs?

Federal agencies using Gogs are primarily affected by this security vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203