← Zurück zur CVE-Suche

CVE-2026-26292

Gitea

Beschreibung

Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration transport protections for those LFS requests.

CVSS 9.8EPSS 0.482%Risiko 1.02
Quelle öffnen
Veröffentlicht
2026-07-03 21:16:58
Betroffene Versionen
<1.25.5
Typ
Webanwendung
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H