References https://www.juniper.net/us/en/threatlabs/ips-signatures/detail.HTTP:DIR:DIR-GOGS-GIT.html https://github.com/gogs/gogs/issues/7002 https://www.ithome.com.tw/news/172793 https://www.tenablecloud.cn/plugins/nessus/286268 https://www.fortiguard.com/encyclopedia/ips/51705 https://www.wiz.io/blog/wiz-research-gogs-cve-2025-8110-rce-exploit https://ridgesecurity.ai/blog/is-your-git-service-safe-how-a-gogs-path-traversal-vulnerability-enables-remote-code-execution-cve%E2%80%912025%E2%80%918110 https://www.cgu.edu.tw/ic/Subject/Detail/74573?nodeId=12683 https://www.knowsafe.com/ti/info/0/992033 https://www.sentinelone.com/vulnerability-database/cve-2026-24135/ https://github.com/gogs/gogs/security/advisories/GHSA-qf5v-rp47-55gg
Related VulnerabilitiesPoCCVE-2026-52806: Gogs <= 0.14.2 - Authenticated RCE via git rebase Argument InjectionGogs /api/v1/orgs/:orgname/teams 信息泄露漏洞(CVE-2026-52815)PoCCVE-2026-52815: Gogs < 0.14.3 - Unauthenticated Organization Teams DisclosurePoCCVE-2026-30824: Flowise - NVIDIA NIM Endpoints Missing AuthenticationGogs Gogs 未授权 命令注入漏洞PoCCVE-2025-8110: Gogs <= 0.13.3 - Remote Code ExecutionPoCCVE-2014-8682: Gogs (Go Git Service) - SQL InjectionPoCCVE-2018-18925: Gogs (Go Git Service) 0.11.66 - Remote Code ExecutionPoCCVE-2020-15867: Gogs 0.5.5 - 0.12.2 - Remote Code ExecutionPoCCVE-2022-0415: Gogs <0.12.6 - Remote Command ExecutionPoCCVE-2022-0870: Gogs <0.12.5 - Server-Side Request Forgery