Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <c4c36909-751f-416b-9e65-7dabf6d265a9@linuxlounge.net>
Date: Thu, 11 Dec 2025 17:07:50 +0100
From: Martin Weinelt <martin@...uxlounge.net>
To: oss-security@...ts.openwall.com
Subject: Re: CVE-2025-8110 in Gogs self-hosted git service

On 12/11/25 16:33, Jakub Wilk wrote:
> * Alan Coopersmith <alan.coopersmith@...cle.com>, 2025-12-10 15:18:
>> https://github.com/gogs/gogs offers a MIT-licensed self-hosted git 
>> service.
> 
> Gogs has a couple of notable forks: Gitea, Forgejo.
> Does anyone know if they are affected?
> 

Per gusted, a Forgejo developer, the relevant code was rewritten way 
back in https://github.com/go-gitea/gitea/pull/6314.

People have since tried to attack it, but have not been successful.

That means Forgejo and Gitea are most likely unaffected.

---

Martin Weinelt

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.