CRITICAL9.8
GHSA-rc56-rj3f-xggf
Gitea LFS mirror operations bypass migration HTTP transport protections
Quick fix
GHSA-rc56-rj3f-xggf — code.gitea.io/gitea: upgrade to the fixed version with the command below.
go get code.gitea.io/gitea@v1.25.5Details
Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration transport protections for those LFS requests.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-26292[ADVISORY]
- https://github.com/go-gitea/gitea/pull/36665[WEB]
- https://github.com/go-gitea/gitea/pull/36691[WEB]
- https://github.com/go-gitea/gitea/commit/996cc12bf7d54ae2326f20b4211fff70eb31e74a[WEB]
- https://github.com/go-gitea/gitea/commit/bcd253a310115045d3ec5e8168a953fbee34dd28[WEB]
- https://blog.gitea.com/release-of-1.25.5[WEB]
- https://github.com/go-gitea/gitea[PACKAGE]
- https://github.com/go-gitea/gitea/releases/tag/v1.25.5[WEB]