
Critical Unpatched Gogs Vulnerability (CVE-2025-8110) Actively Exploited in the Wild
A high-severity vulnerability in Gogs, tracked as CVE-2025-8110 with a CVSS score of 8.7, is currently being actively exploited in the wild. This vulnerability involves uncontrolled file writing in the file update API of the self-hosted Git service written in Go. According to reports, this flaw affects over 700 instances accessible on the Internet and is being exploited to potentially compromise exposed instances. As of now, no patch is available, although a fix is reportedly in development. The lack of a patch combined with active exploitation makes this vulnerability particularly dangerous. Organizations using Gogs should immediately assess their exposure and consider implementing mitigating measures, such as restricting access to the Gogs instance or monitoring for unusual activity. This situation underscores the critical importance of timely patching and the need for robust monitoring to detect and respond to exploitation attempts.