Gitea | v1.25.5

Gitea v1.25.5 released on 13-03-2026


Gitea v1.25.5 is out now. Admins and self-hosters benefit from security and toolchain updates plus a range of fixes that harden request handling and restore expected access control behaviour.

See the Gitea GitHub releases or Gitea Cloud (https://cloud.gitea.com) for the full notes and detailed upgrade instructions.

What’s in this release

  • Security and toolchain updates: Go toolchain updated (Go 1.25.6, and 1.25.8 for the v1.25 line), mitigations for redirect bypasses via backslash-encoded paths, fixes preventing users changing another user’s primary email, and OAuth2 fixes for authorization code expiry/reuse and S256 handling; the default security-check is now informational-only.
  • Permissions and API visibility fixes: corrected permission checks for release drafts, updating/rebasing pull request branches, track-time and issue ID checks, and org-member visibility for hidden members and private organisations; forwarded-proto handling for public URL detection fixed.
  • Repository, mirroring, LFS and git ops improvements: stricter validation for repository creation, migration HTTP transport for mirror LFS, fixes for mirror pushes including wikis, LFS GC fixes, path-resolving and release-asset dump fixes, a git-grep search timeout, and an upgrade of go-git to 5.16.5.

Upgrade notes

  • Toolchain change: the Go toolchain has been updated to 1.25.6 (and 1.25.8 for v1.25). Check your build and CI toolchain compatibility before upgrading and follow the release notes for build details.
  • Gitea Cloud auto-upgrade: Gitea Cloud instances will be automatically upgraded to v1.25.5 during the scheduled maintenance window; no specific rollback instructions are provided — follow your usual rollback procedures if necessary.

Try the upgrade and share feedback on the project’s issue tracker or community channels — reports on any regressions or remaining edge cases are especially useful.

Related posts

Vector | vdev-v0.3.3

Vector vdev v0 3 3: patch release with crash, leak and parsing fixes, connector and tooling improvements, upgrade notes on prechecks, rolling updates, compat

Loki | v3.7.2

Loki v3 7 2: security and CVE fixes, updated S3 client to aws sdk v1 97 3, ruler panic fix for unset validation scheme, S3 Object Lock sends SHA256 checksum

Loki | v3.7.2

Loki v3 7 2: Patch release with CVE fixes, AWS S3 SDK update, ruler panic fix, S3 Object Lock SHA256 checksum support