Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability

Unpatched Gogs Rebase Injection Remote Code Execution Risk

Updated 28.05.2026 17:25
Case score 59
Case score 59 Members 1 Latest activity 28.05.2026 17:25
Members 1 First seen 28.05.2026 17:25 Last seen 28.05.2026 17:25 Updated 28.05.2026 17:25

Overview

An unpatched **Gogs** argument injection flaw in the **Rebase before merging** workflow can give an authenticated, non-admin user remote code execution on self-hosted servers. The issue affects **Gogs 0.14.2** and **0.15.0+dev**, and default deployments with open registration and unrestricted repository creation lower the barrier to reaching the vulnerable path. Public technical details describe server compromise risk, exposure of private repositories and secrets, and potential code tampering. The maintainers had acknowledged the report, but no patch or remediation timeline was available at disclosure time, while more than **2,400** Internet-facing Gogs servers were noted as exposed overall.

Signals

1 derived
Remediation
Patch No Patch

Member happenings

1 related
Vulnerability Gogs self-hosted Git service argument injection zero-day remote code execution flaw
Updated 28.05.2026 17:25 Lead Contribution 59
Data Type Passwords Patch No Patch

An **unpatched zero-day** in **Gogs** exposes **Internet-facing instances** to **remote code execution** and possible credential theft. The flaw is an **argument injection** bug in the **Rebase before merging** path, and it affects **Gogs 0.14.2** and **0.15.0+dev**. Because default configurations allow **open registration** and unlimited repository creation, a non-admin attacker can reach the exploit chain with basic account access.