Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-26292: Gitea lets LFS sync ignore transport restrictions
CVE-2026-26292 · published 3 months ago
Summary
Versions of Gitea released before the latest update do not apply the configured transport rules when large file storage (LFS) data is pushed or when repository mirrors are synchronized. This means an attacker could bypass those rules and move data in ways the administrator did not intend. Updating Gitea to the newest version resolves the issue.
What to do
- Update gitea code.gitea.io/gitea to version 1.25.5.
- Update code.gitea.io gitea to version 1.25.5.
- Update gitea gitea open source git server to version 1.25.5 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | gitea | gitea open source git server | < 1.25.5 |
| Go | gitea | code.gitea.io/gitea |
< 1.25.5 Fix: upgrade to 1.25.5
|
| go | code.gitea.io | gitea |
< 1.25.5 Fix: upgrade to 1.25.5
|
Original advisory text
Gitea LFS mirror synchronization bypasses migration HTTP transport restrictions
Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration transport protections for those LFS requests.
References
- https://github.com/go-gitea/gitea/pull/36665 Patch
- https://github.com/go-gitea/gitea/pull/36691 Patch
- https://blog.gitea.com/release-of-1.25.5/ Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/26xxx/CVE-2026-26292... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-26292 Vendor Advisory
- https://github.com/go-gitea/gitea/commit/996cc12bf7d54ae2326f20b4211fff70eb31e74...
- https://github.com/go-gitea/gitea/commit/bcd253a310115045d3ec5e8168a953fbee34dd2...
- https://blog.gitea.com/release-of-1.25.5
- https://github.com/go-gitea/gitea Product
- https://github.com/advisories/GHSA-rc56-rj3f-xggf
- https://github.com/go-gitea/gitea/releases/tag/v1.25.5 Vendor Advisory
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.8
Critical
Type
CWE-284Improper Access Control
Timeline
Published3 Jul 2026
Updated11 Oct 2026
First seen3 Jul 2026
Sources
CVE-2026-26292 · NVD
CVE-2026-26292 · MITRE
GHSA-rc56-rj3f-xggf · OSV
GO-2026-6344 · OSV
GHSA-rc56-rj3f-xggf · GHSA
CVE-2026-26292 · OSV
Track software like this
Free during beta