CISA has ordered federal agencies to stop using Gogs or lock it down immediately after a high-severity vulnerability in the self-hosted Git service was added to its Known Exploited Vulnerabilities (KEV) catalog. The US cybersecurity agency added the path traversal flaw to the KEV list on Monday, triggering urgent remediation requirements for federal civilian executive branch (FCEB) agencies. CISA's advisory warns that the vulnerability is being weaponized in attacks, and that agencies should apply mitigations or simply stop using the product if workarounds aren't available. "This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise," CISA said in its alert. The vulnerability, tracked as CVE-2025-8110, was first brought to light by Wiz security researchers in December who stumbled on the unpatched flaw in July while investigating malware on an infected machine. The bug allows authenticated users to bypass protections and overwrite arbitrary files on the host system, effectively granting remote code execution. More than 700 internet-exposed Gogs instances were already confirmed compromised in ongoing attacks at the time of disclosure, with upwards of 1,400 servers found reachable online. Gogs, which is written in Go and allows users to host Git repositories on their own servers or cloud infrastructure, has yet to ship a fix for the flaw, leaving users scrambling for stopgaps such as disabling open reg...
Federal agencies told to fix or ditch Gogs as exploited zero-day lands on CISA hit list
The Register
·Carly Page
·Published Jan 13, 2026
·Updated
Affected Software
1 affected component
Gogs Gogs<all
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a high-severity zero-day vulnerability in the self-hosted Git service Gogs, which has been added to CISA's Known Exploited Vulnerabilities catalog.
2
What security implications are discussed in the article?
Federal agencies are urged to stop using Gogs or implement immediate safeguards due to the potential risks posed by the identified vulnerability.
3
What actions has CISA recommended regarding Gogs?
CISA has recommended that federal agencies either discontinue the use of Gogs or lock it down to prevent exploitation.
4
What type of software is Gogs categorized as?
Gogs is categorized as a self-hosted Git service software.
5
Who is affected by this vulnerability in Gogs?
Federal agencies using Gogs are primarily affected by this security vulnerability.