CVE-2026-26292: Gitea LFS mirror synchronization bypasses migration HTTP transport restrictions
Published Jul 3, 2026
·Updated
Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration transport protections for those LFS requests.
Affected Software
1 affected component
Gitea Gitea<1.25.5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Giteato a version that resolves this vulnerability.Fixed in 1.25.5
Event History
Jul 3, 2026
CVE Published
via MITRE·08:19 PM
Data Sourced
via MITRE·08:19 PM
DescriptionWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-26292?
CVE-2026-26292 has a risk rating of 33, indicating a moderate severity level.
2
How do I fix CVE-2026-26292?
To fix CVE-2026-26292, upgrade to Gitea version 1.25.5 or later.
3
What are the implications of CVE-2026-26292?
CVE-2026-26292 allows Gitea LFS mirror synchronization to bypass configured migration HTTP transport protections.
4
Which versions of Gitea are affected by CVE-2026-26292?
Gitea versions prior to 1.25.5 are affected by CVE-2026-26292.
5
Is there a workaround for CVE-2026-26292?
There is no specific workaround mentioned for CVE-2026-26292 other than upgrading to the latest version.