Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Gogs Flaw Allows Silent Overwriting of LFS Objects

Critical Gogs Flaw Allows Silent Overwriting of LFS Objects

Posted on March 11, 2026 By CWS

A critical vulnerability has been identified in Gogs, a widely used open-source Git service, which permits attackers to undetectably overwrite Large File Storage (LFS) objects.

Understanding the Gogs Vulnerability

Labeled as CVE-2026-25921, this high-severity flaw has been assigned a perfect CVSS 3.1 score of 10.0, indicating its potential to facilitate severe software supply-chain attacks. Currently, it impacts Gogs versions 0.14.1 and earlier, with no official fix released yet.

If this vulnerability is exploited, attackers can alter essential binaries, datasets, or software builds within any repository on a shared server, all without generating any alerts.

The Root Cause Explained

The critical issue arises from two main design weaknesses in Gogs’ LFS architecture:

  • Lack of Storage Isolation: All LFS objects are stored in a single, shared location, without repository-specific isolation.
  • Missing Hash Verification: Gogs fails to verify if the uploaded file’s content matches its stated SHA-256 hash.

These weaknesses mean that an attacker only requires knowledge of a target file’s hash to upload a manipulated file, such as a compromised software installer, into their repository. The server, mistaking it for a routine retry, overwrites the legitimate file with the attacker’s version.

Implications and Interim Measures

The implications of CVE-2026-25921 are severe, as the attack complexity is low, requires no special privileges, and can occur without user involvement. Legitimate users downloading the affected LFS objects may unknowingly receive tampered files, leading to potential supply-chain compromises.

In the absence of an official patch, organizations using self-hosted Gogs instances need to enforce strict security measures. This includes limiting account creation and LFS upload permissions to trusted users and implementing external scripts to periodically verify the integrity of critical LFS files.

The eventual solution from developers will necessitate strict verification of the SHA-256 hash of all uploaded LFS objects to ensure data authenticity before server storage.

Stay informed with daily cybersecurity updates by following us on Google News, LinkedIn, and X. Contact us to feature your cybersecurity stories.

Cyber Security News Tags:CVE-2026-25921, CWE-345, Cybersecurity, Git, Gogs, hash verification, LFS, Open Source, Security, self-hosted, Software, storage isolation, supply chain attack, Vulnerability

Post navigation

Previous Post: Malicious Rust Crates and AI Bot Threaten Developer Secrets
Next Post: Siemens and Schneider Lead ICS Patch Tuesday Updates

Related Posts

AI Bug Reports Overwhelm Linux Security List AI Bug Reports Overwhelm Linux Security List Cyber Security News
Retail Finance Giant SitusAMC Data Breach Exposes Accounting Records and Legal Agreements Retail Finance Giant SitusAMC Data Breach Exposes Accounting Records and Legal Agreements Cyber Security News
Chrome 151 Update Addresses 382 Security Flaws Chrome 151 Update Addresses 382 Security Flaws Cyber Security News
Discord Data Breach – 1.5 TB of Data and 2 Million Government ID Photos Extorted Discord Data Breach – 1.5 TB of Data and 2 Million Government ID Photos Extorted Cyber Security News
SonicWall Urges Immediate Fixes for Critical Firewall Flaws SonicWall Urges Immediate Fixes for Critical Firewall Flaws Cyber Security News
MuddyWater Using New Malware Toolkit to Deliver Phoenix Backdoor Malware to International Organizations MuddyWater Using New Malware Toolkit to Deliver Phoenix Backdoor Malware to International Organizations Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Foxit Vulnerability Allows SYSTEM Privilege Escalation
  • Critical Bing Images Flaws Patched Amid Security Concerns
  • Certighost Flaw in AD CS Allows Domain Compromise
  • Tego AI Reveals Second Security Issue in Claude Software
  • SourTrade Malvertising Evades Detection with Unique Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Foxit Vulnerability Allows SYSTEM Privilege Escalation
  • Critical Bing Images Flaws Patched Amid Security Concerns
  • Certighost Flaw in AD CS Allows Domain Compromise
  • Tego AI Reveals Second Security Issue in Claude Software
  • SourTrade Malvertising Evades Detection with Unique Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark