← All CVEs

CVE-2026-26292

critical · 9.8

Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration transport protections for those LFS requests.

9.8
CVSS
0.7%
EPSS (exploit prob.)
50th
EPSS percentile
2026-07-03
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-284

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-26292