CVE-2026-26292

Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration transport protections for those LFS requests.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-03 21:16

Updated : 2026-07-07 18:16


NVD link : CVE-2026-26292

Mitre link : CVE-2026-26292

CVE.ORG link : CVE-2026-26292


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control