Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-26292: Gitea LFS Push Allows Bypassing Configured Security
CVE-2026-26292
CVE-2026-26292
Summary
Versions of Gitea before 1.25.5 allow attackers to bypass security restrictions for large file transfers. This can allow unauthorized access to sensitive data. To fix this, update to Gitea version 1.25.5 or later.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| gitea | gitea open source git server | < 1.25.5 |
Original title
Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration transport protections for those LFS requests.
Original description
Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration transport protections for those LFS requests.
Vulnerability type
CWE-284
Improper Access Control
Published: 3 Jul 2026 · Updated: 23 Jul 2026 · First seen: 3 Jul 2026