GHSA-rc56-rj3f-xggfCriticalCVSS 9.8

Gitea LFS mirror operations bypass migration HTTP transport protections

Published
July 3, 2026
Last Modified
September 1, 2026

🔗 CVE IDs covered (1)

📋 Description

Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration transport protections for those LFS requests.

🎯 Affected products1

  • go/code.gitea.io/gitea:< 1.25.5

🔗 References (8)