{"id":177834,"date":"2026-01-14T03:45:04","date_gmt":"2026-01-14T08:45:04","guid":{"rendered":"https:\/\/testing.news-you-need.com\/index.php\/2026\/01\/14\/cisa-flags-actively-exploited-gogs-vulnerability-with-no-patch\/"},"modified":"2026-01-14T03:45:10","modified_gmt":"2026-01-14T08:45:10","slug":"cisa-flags-actively-exploited-gogs-vulnerability-with-no-patch","status":"publish","type":"post","link":"https:\/\/testing.news-you-need.com\/index.php\/2026\/01\/14\/cisa-flags-actively-exploited-gogs-vulnerability-with-no-patch\/","title":{"rendered":"CISA Flags Actively Exploited Gogs Vulnerability With No Patch"},"content":{"rendered":"<p><a href=\"https:\/\/www.infosecurity-magazine.com\/news\/cisa-flags-exploited-gogs-flaw-no\/\">CISA Flags Actively Exploited Gogs Vulnerability With No Patch<\/a><\/p>\n<p><a href=\"https:\/\/www.infosecurity-magazine.com\/news\/cisa-flags-exploited-gogs-flaw-no\/\">https:\/\/www.infosecurity-magazine.com\/news\/cisa-flags-exploited-gogs-flaw-no\/<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-01-13 11:45:03<\/a><\/p>\n<p>Source Domain: <a href=\"www.infosecurity-magazine.com\">www.infosecurity-magazine.com<\/a><\/p>\n<p><strong>Summary:<\/strong><br \/>\nA high-severity security flaw in the self-hosted Git service Gogs, known as CVE-2025-8110, is being actively exploited in the wild, according to a warning from the US Cybersecurity and Infrastructure Security Agency (CISA). This vulnerability is caused by improper symbolic link handling in Gogs&#8217; PutContents API and allows authenticated users to overwrite files outside a repository, potentially leading to remote code execution (RCE). Discovered by Wiz researchers during an investigation into a malware infection, the exploit targets Gogs servers exposed to the internet, with over 700 instances identified as compromised. With no official patch available yet, mitigation strategies such as disabling open registration, restricting access using VPNs, and monitoring unusual activities are recommended. CISA has mandated that federal agencies apply the necessary mitigations by February 2026.<\/p>\n<p><strong>Key Points:<\/strong><\/p>\n<ul>\n<li>A high-severity vulnerability tracked as CVE-2025-8110 in Gogs, rated 8.7 on CVSS v4.0, allows remote code execution and is being actively exploited.<\/li>\n<li>The flaw was first identified by Wiz researchers while investigating a malware infection, and the agency reported over 700 compromised instances.<\/li>\n<li>Although no official patch is available yet, fixes will be included in future Gogs releases once new images are built.<\/li>\n<li>Security mitigations such as disabling open registration and restricting server access using a VPN are strongly recommended.<\/li>\n<li>CISA has mandated federal civilian agencies to apply defensive measures by February 2026 and has added the vulnerability to its Known Exploited Vulnerabilities catalog.<\/li>\n<\/ul>\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>CISA Flags Actively Exploited Gogs Vulnerability With No Patch https:\/\/www.infosecurity-magazine.com\/news\/cisa-flags-exploited-gogs-flaw-no\/ Publish Date: 2026-01-13 11:45:03 Source&#8230;<\/p>\n","protected":false},"author":1,"featured_media":177835,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/assets.infosecurity-magazine.com\/webpage\/og\/63db1ff8-47b1-4a5e-8bc6-87b676353990.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[24,31,32,27],"class_list":["post-177834","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity","tag-exploit","tag-malware","tag-vulnerability"],"_links":{"self":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/177834"}],"collection":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=177834"}],"version-history":[{"count":1,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/177834\/revisions"}],"predecessor-version":[{"id":177836,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/177834\/revisions\/177836"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/177835"}],"wp:attachment":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=177834"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=177834"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=177834"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}