Gogs Has a CVSS 9.4 Zero-Day With No Patch. A Metasploit Module Is Out.
Any user can get remote code execution on a Gogs server through a malicious branch name. The maintainer was told in March. It's still not fixed. There's a public exploit. Self-hosters, good luck.