v1.24.7
go-gitea/giteav1.24.7Oct 25, 2025by GiteaBot
AI Summary
A security-focused release addressing critical vulnerabilities in LFS authentication and symlink handling, alongside fixes for logging and OAuth2.
Key Highlights
- Fixed LFS authentication bypass and symlink bypass vulnerabilities
- Fixed password leak in log messages
- Fixed missed return in OAuth2
Full Release Notes
* SECURITY * Refactor legacy code, fix LFS auth bypass, fix symlink bypass (#35708) (#35713) * Fix password leak in log messages (#35584) (#35665) * Fix a missed return in OAuth2 (#35655) (#35671) * BUGFIXES * Fix inputing review comment will remove reviewer (#35591) (#35664) * TESTING * Mock external service in hcaptcha TestCaptcha (#35604) (#35663) * Fix build (#35669) Instances on **[Gitea Cloud](https://cloud.gitea.com)** will be automatically upgraded to this version during the specified maintenance window.