INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Gogs Patches Critical Zero-Day Flaw Enabling Remote Code Execution

| 2026-06-08 16:18 CRITICAL MEDIUM EXPLOITED VULNERABILITY VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
On June 8, 2026, a critical zero-day vulnerability was discovered in Gogs, allowing authenticated attackers without admin privileges to exploit an argument injection flaw that affects all releases up to and including version 0.14.2 and 0.15.0+dev. The vulnerability can be exploited by creating a new repository with rebase enabled, which is not effectively defended against by disabling "Rebase before merging" per-repo under Settings > Advanced due to malicious users having admin access or owning the repo. Gogs maintainers released version 0.14.3 on June 7 to patch this flaw and Rapid7 recommends immediate upgrade for all users; mitigation measures include restricting user registration and repository creation, which can be set via [IOC HIDDEN • LOGIN REQUIRED] files.
Technical Mitigations AI-generated
• Restrict user registration (DISABLE_REGISTRATION = true in <a href="/auth/login?next=/detail/frNEcp4BHUyMcQl6C0Bw" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN &bull; LOGIN REQUIRED]</span></a>) to prevent untrusted users from creating accounts. • Restrict repository creation (MAX_CREATION_LIMIT = 0 in <a href="/auth/login?next=/detail/frNEcp4BHUyMcQl6C0Bw" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN &bull; LOGIN REQUIRED]</span></a>) to prevent users from creating their own repos. • Audit rebase merge settings: Disable "Rebase before merging" per-repo under Settings > Advanced.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

ap•••••.ini
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2024-39930CVE-2024-39930 CVE-2024-39933CVE-2024-39933 CVE-2024-39932CVE-2024-39932 CVE-2026-26194CVE-2026-26194 CVE-2025-8110CVE-2025-8110
Target & Sectors
EUROPE EUROPE
Incident Timeline
‎2026/06/08
Threat actors exploited a previously unpatched zero-day vulnerability in Gogs, allowing authenticated attackers without admin privileges to gain remote code execution.
infrastructure 0.14.2
infrastructure 0.15.0
infrastructure 0.14.3
infrastructure 2,300 exposed Gogs servers
financial 312 Europe
infrastructure 1,000 IP addresses
infrastructure 2,400 Gogs servers
financial 319 Europe
financial 8301 request
Tactical Metrics
Metrics
infrastructure
‎0.14.2
Software Version
Metrics
infrastructure
‎0.15.0
Software Version
Metrics
infrastructure
‎0.14.3
Software Version
Metrics
infrastructure
2,300
Exposed Gogs Servers
Metrics
financial
312
Europe
Metrics
infrastructure
1,000
Ip Addresses
Metrics
financial
8,301
Request
Metrics
infrastructure
2,400
Gogs Servers
Metrics
financial
319
Europe
Intelligence Sources
BleepingComputer 2026-05-28
BleepingComputer 2026-06-08