Security Advisory
CVE-2026-26292
9.8
CRITICAL
Vulnerability Description
Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration transport protections for those LFS requests.
Published Date
July 3, 2026
Official Source
NIST NVD Advisory