Open source Git service Gogs is affected by a critical-severity zero-day vulnerability that exposes servers to remote code execution.

Two months after Rapid7 discovered the hole in the Git service, the project maintainer has yet to patch the bug.

CVE-2026-27771, an access control vulnerability in Gitea, exposed over 30,000 deployments to unauthorized access.

An unpatched zero-day vulnerability in the Gogs self-hosted Git service can allow attackers to gain remote code execution (RCE) on Internet-facing instances.

Gogs 9.4 CVSS flaw exploits git rebase injection on 1,141 exposed instances, enabling remote code execution.

Angreifer können Gogs-Server in den Standardeinstellungen mit Schadcode attackieren. Bislang können Admins Systeme nur über einen Workaround schützen.

Open source Git service Gogs is affected by a critical-severity zero-day vulnerability that exposes servers to remote code execution.

Researcher reported the vuln in March. Maintainers haven't responded to his messages since