Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-26292: Gitea lets LFS sync ignore transport restrictions

CVE-2026-26292 · published 3 months ago
Summary

Versions of Gitea released before the latest update do not apply the configured transport rules when large file storage (LFS) data is pushed or when repository mirrors are synchronized. This means an attacker could bypass those rules and move data in ways the administrator did not intend. Updating Gitea to the newest version resolves the issue.

What to do
  • Update gitea code.gitea.io/gitea to version 1.25.5.
  • Update code.gitea.io gitea to version 1.25.5.
  • Update gitea gitea open source git server to version 1.25.5 or later.
Affected software
Ecosystem VendorProductAffected versions
– gitea gitea open source git server < 1.25.5
Go gitea code.gitea.io/gitea < 1.25.5
Fix: upgrade to 1.25.5
go code.gitea.io gitea < 1.25.5
Fix: upgrade to 1.25.5
Original advisory text
Gitea LFS mirror synchronization bypasses migration HTTP transport restrictions
Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration transport protections for those LFS requests.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-284Improper Access Control
Timeline
Published3 Jul 2026
Updated11 Oct 2026
First seen3 Jul 2026
Track software like this
Free during beta