CVE-2025-64175 | Gogs up to 0.13.3 2FA Recovery Code Validation improper authentication (GHSA-p6x6-9mx6-26wj / WID-SEC-2026-0338)
A vulnerability categorized as critical has been discovered in Gogs up to 0.13.3. This impacts an unknown function of the component 2FA Recovery Code Validation. Executing a manipulation can lead to improper authentication.
This vulnerability is handled as CVE-2025-64175. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.