# Gitea 1.25.5 is released

DevFeed: [Gitea 1.25.5 is released](<https://devfeed.tech/articles/gitea-1-25-5-is-released-54941.md>)

Original publisher: [Read original article](<https://blog.gitea.com/release-of-1.25.5/>)

Author: lunny

Published: 2026-03-16T18:36:00Z

Content type: release

Language: en

Sources: [Gitea Blog](<https://devfeed.tech/sources/gitea-blog.md>)

Topics: [Gitea](<https://devfeed.tech/topics/gitea.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [bug](<https://devfeed.tech/topics/bug.md>), [OAuth 2.0](<https://devfeed.tech/topics/oauth2.md>), [upgrade](<https://devfeed.tech/topics/upgrade.md>), [Pull Request](<https://devfeed.tech/topics/pull-request.md>), [Repository](<https://devfeed.tech/topics/repository.md>), [HTTP](<https://devfeed.tech/topics/http.md>)

Tags: [authorization](<https://devfeed.tech/tags/authorization.md>), [bug-fixes](<https://devfeed.tech/tags/bug-fixes.md>), [gitea](<https://devfeed.tech/tags/gitea.md>), [http](<https://devfeed.tech/tags/http.md>), [oauth2](<https://devfeed.tech/tags/oauth2.md>), [permission](<https://devfeed.tech/tags/permission.md>), [pull-request](<https://devfeed.tech/tags/pull-request.md>), [release](<https://devfeed.tech/tags/release.md>), [security](<https://devfeed.tech/tags/security.md>), [upgrade](<https://devfeed.tech/tags/upgrade.md>)

## AI overview

Gitea 1.25.5 is a security and bug-fix release that addresses multiple CVEs involving permissions, OAuth2 authorization codes, repository creation validation, pull request branches, HTTP transport, time tracking, path handling, and other functionality.

## Source excerpt

We're excited to announce the release of Gitea 1.25.5! We strongly recommend all users upgrade to this version, as it includes important security fixes, numerous bug fixes, and overall stability improvements. * CVE-2026-25779: Prevent redirect bypasses via backslash-encoded paths ([#36660](https://github.com/go-gitea/gitea/pull/36660)) ([#36716](https://github.com/go-gitea/gitea/pull/36716)). Thanks to @quirmz for the report, and thanks to @lunny for the fix. * CVE-2026-27660: Fix the release draft permission check ([#36659](https://github.com/go-gitea/gitea/pull/36659)) ([#36715](https://github.com/go-gitea/gitea/pull/36715)). Thanks to @anticomputer for the report, and thanks to @lunny for the fix. * CVE-2026-27657: Fix an issue where a user could change another user's primary email address ([#36586](https://github.com/go-gitea/gitea/pull/36586)) ([#36607](https://github.com/go-gitea/gitea/pull/36607)). Thanks to @CsEnox for the report, and thanks to @lunny for the fix. * CVE-2026-26232: Fix OAuth2 authorization code expiry and reuse handling ([#36797](https://github.com/go-gitea/gitea/pull/36797)) ([#36851](https://github.com/go-gitea/gitea/pull/36851)). Thanks to [@sammiee5311](https://github.com/sammiee5311) for the report, and thanks to @lunny for the fix. * CVE-2026-22547: Add validation constraints for repository creation fields ([#36671](https://github.com/go-gitea/gitea/pull/36671)) ([#36757](https://github.com/go-gitea/gitea/pull/36757)). Thanks to @brettm220 for the report, and thanks to @lunny for the fix. * CVE-2026-24690: Fix permission checks for updating or rebasing pull request branches ([#36465](https://github.com/go-gitea/gitea/pull/36465)) ([#36838](https://github.com/go-gitea/gitea/pull/36838)). Thanks to the [CodeThreat Security Research Team](https://github.com/codethreat-sec) and [@Alexander Girgis](https://github.com/AlexanderGirgis) for the report, and thanks to @lunny for the fix. * CVE-2026-26292: Add HTTP transport support for LFS in pu