v1.24.7

go-gitea/giteav1.24.7Oct 25, 2025by GiteaBot

AI Summary

A security-focused release addressing critical vulnerabilities in LFS authentication and symlink handling, alongside fixes for logging and OAuth2.

Key Highlights

  • Fixed LFS authentication bypass and symlink bypass vulnerabilities
  • Fixed password leak in log messages
  • Fixed missed return in OAuth2

Full Release Notes

* SECURITY
  * Refactor legacy code, fix LFS auth bypass, fix symlink bypass (#35708) (#35713)
  * Fix password leak in log messages (#35584) (#35665)
  * Fix a missed return in OAuth2 (#35655) (#35671)
* BUGFIXES
  * Fix inputing review comment will remove reviewer (#35591) (#35664)
* TESTING
  * Mock external service in hcaptcha TestCaptcha (#35604) (#35663)
  * Fix build (#35669)

Instances on **[Gitea Cloud](https://cloud.gitea.com)** will be automatically upgraded to this version during the specified maintenance window.