Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-26292: Gitea LFS Push Allows Bypassing Configured Security

CVE-2026-26292 CVE-2026-26292
Summary

Versions of Gitea before 1.25.5 allow attackers to bypass security restrictions for large file transfers. This can allow unauthorized access to sensitive data. To fix this, update to Gitea version 1.25.5 or later.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
gitea gitea open source git server < 1.25.5
Original title
Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration transport protections for those LFS requests.
Original description
Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration transport protections for those LFS requests.
Vulnerability type
CWE-284 Improper Access Control
Published: 3 Jul 2026 · Updated: 23 Jul 2026 · First seen: 3 Jul 2026