Gitea · Gitea · CVE-2026-26292
**Name of the Vulnerable Software and Affected Versions**
Gitea versions prior to 1.25.5
**Description**
LFS push and sync mirror operations do not utilize the migration HTTP transport. This behavior allows LFS requests to bypass the configured migration transport protections.
**Recommendations**
Update Gitea to version 1.25.5 or later.