Gitea v1.25.4 for Cloud is released

We are pleased to announce the release of Gitea v1.25.4 for Gitea Cloud!
All Gitea Cloud instances are automatically upgrading to v1.25.4 during your configured maintenance window, with no action required.
Security fixes
Gitea v1.25.4 addresses the following advisories:
- CVE-2026-20736: Release attachments must belong to the intended repo.
- CVE-2026-20750: Fix permission check on org project operations.
- CVE-2026-20883: Add more check for stopwatch read or list.
- CVE-2026-20904: Fix openid setting check.
- CVE-2026-20888: Fix cancel auto merge bug.
- CVE-2026-20912: Fix delete attachment check.
- CVE-2026-20897: LFS locks must belong to the intended repo.
- CVE-2026-0798: Clean watches when make a repository private and check permission when send release emails.
- CVE-2026-20800: Fix bug on notification read.
Release notes
For the complete release notes, please refer to the links below: