CVE-2025-64175Disclosure(gogs / gogs)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, Gogs’ 2FA recovery code validation does not scope codes by user, enabling cross-account bypass. If an attacker knows a victim’s username and password, they can use any unused recovery code (e.g., from their own account) to bypass the victim’s 2FA. This enables full account takeover and renders 2FA ineffective in all environments where it's enabled.. This issue has been patched in versions 0.13.4 and 0.14.0+dev.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gogs

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-02-06); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
gogs

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-06: 2Mentions · 2026-02-10: 1Mentions · 2026-05-02: 1Technical Details · 2026-02-06: 2Technical Details · 2026-02-10: 102-0602-1005-02
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-062
Disclosure2
2026-02-101
Disclosure1
2026-05-021
General1
Full discourse4 posts
  • Hunter@HunterMapping
    Disclosure

    🚨Alert🚨 CVE-2025-64111 & CVE-2025-64175 & CVE-2026-24135 : Critical Gogs Flaws Allow RCE & 2FA Bypass. 📊 319K+ Services are found on the http://hunter.how yearly. 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22Gogs%22 👇Query HUNTER : http://product.name="Gogs" 📰Refer:https://securityonline.info/triple-threat-critical-gogs-flaws-cvss-9-3-allow-rce-2fa-bypass/ #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    The alert announces three critical Gogs CVEs (CVE‑2025‑64111, CVE‑2025‑64175, CVE‑2026‑24135) that enable RCE and 2FA bypass, with over 319k affected services, but provides no PoC, exploit code, or patch information.

    115038163.4K
    25.4K followersView on X
  • ~lyn@lynettdoteth
    General

    @tiredhungryangr One? CVE-2026-2796, CVE-2026-24881, CVE-2026-24882, CVE-2025-32988, CVE-2025-32989, CVE-2025-64175, CVE-2026-25242, CVE-2026-28357, CVE-2026-28359, CVE-2026-26216, CVE-2026-26217, CVE-2026-25946, CVE-2026-32110, CVE-2026-30930, CVE-2026-30928, CVE-2026-32596...

    Post summary

    The tweet simply lists a series of CVE identifiers without providing additional context, details, or actionable information.

    10000932
    825 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-64175 Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, Gogs’ 2FA recovery code validation does not scope codes by user, enabling cross-account b… https://www.cve.org/CVERecord?id=CVE-2025-64175

    Post summary

    A new vulnerability (CVE‑2025‑64175) has been disclosed in Gogs 0.13.3 and earlier: 2FA recovery codes are not user‑scoped, potentially enabling cross‑account attacks.

    00010166
    56.5K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2025-64175: Gogs 2FA Bypass: The Universal Skeleton Key in Your Git Server A critical logic error in the Gogs self-hosted Git service allows attackers to bypass Two-Factor Authentication (2FA) by using recovery codes belonging to a different accou... https://cvereports.com/reports/CVE-2025-64175

    Post summary

    The report announces a critical logic flaw in Gogs that lets attackers bypass two‑factor authentication using cross‑account recovery codes, but it does not provide a PoC, exploit code, or evidence of active exploitation.

    0000055
    27 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgogsgogs---

Explore more