Skip to content

Gitea Enterprise 26.4.9 is released

Gitea Enterprise 26.4.9 is released
4 min read

We are excited to announce the release of Gitea Enterprise 26.4.9! This release rolls up the 26.4.5, 26.4.6, 26.4.7, 26.4.8 and 26.4.9 patch releases. It completes the repository-scoped DevOps dashboard filters, extends audit logging to file-level push/pull activity and directory downloads, hardens account linking, and makes LDAP user-group synchronization work on large directories.

Audit & Compliance

  • Push and pull audit records now list the files involved
  • Downloading a directory is recorded in the audit log
  • A sign_in_failed audit entry is written when a prohibited account attempts to sign in

Directory & Authentication

  • LDAP group filters accept *
  • LDAP user-group synchronization scales to large directories
  • Authentication info is normalized before an account is linked automatically, and an inactive account is activated after a successful link
  • The sign-in page lists OAuth2 providers in a deterministic order

Major Breaking changes

No breaking changes are introduced between 26.4.4 and 26.4.9. The embedded Gitea remains on v1.26.4, unchanged since Gitea Enterprise 26.4.0. As always, back up your database and repository storage before upgrading.

Major Highlights

🚀 Repository-scoped DevOps dashboard filters

The DevOps dashboard filters are now complete at repository scope, so a repository dashboard can be narrowed the same way instance-level and organization-level dashboards can. Metrics, time ranges and widget selection stay consistent across all three scopes.

🚀 File-level audit trail for push and pull

Push and pull audit records now capture the files that were transferred, and downloading a directory produces its own audit entry. Together with the sign_in_failed entry written when a prohibited account tries to sign in, this closes the remaining gaps auditors usually ask about when reviewing code-movement evidence.

🚀 Smoother — but still reviewed — account linking

When an existing user links an external identity, the authentication information is normalized first so the match is reliable, and an account that was left inactive by LDAP synchronization is activated once the link succeeds. This keeps the "new LDAP users start inactive" policy introduced in 26.4.4 while removing the manual step for users who prove their identity through a configured provider.

🚀 LDAP synchronization for large directories

LDAP user-group synchronization was reworked to scale to large directories instead of resolving group membership one entry at a time, and group filters may now contain *. Instances with tens of thousands of directory entries should see substantially shorter synchronization runs.

🚀 Built-in OAuth2 application for the Gitea mobile app

A built-in OAuth2 application for the official Gitea mobile app is now pre-registered, so administrators no longer need to create and distribute an application registration before their users can sign in from mobile.

Security

The 26.4.x line stays on Gitea v1.26.4, which contains the security fixes published for Gitea 1.26.3 and 1.26.4:

  • CVE-2026-20896: The Docker images shipped a REVERSE_PROXY_TRUSTED_PROXIES = * default, which let any source IP impersonate any user via the X-WEBAUTH-USER header.
  • CVE-2026-22874: The default allow-list filter used by webhooks and migrations was too permissive, leaving an incomplete SSRF protection that could reach internal addresses.
  • CVE-2026-27775: The pre-receive hook cached the first ref's permission result, letting a per-branch maintainer-edit grant escalate to full repository write.
  • CVE-2026-24451: Fork synchronization could pull commits made after the parent repository was switched from public to private.
  • CVE-2026-20779: TOTP passcodes were not strictly single-use across web login, password reset and the Basic-Auth OTP surface.
  • CVE-2026-28740: Cross-repository LFS object reuse did not require Code-unit access, so a non-Code grant could authorize private source objects.
  • CVE-2026-27761: The RSS/Atom feed endpoints did not enforce repository token scope, so a token without repository scope could read private repository commit data.
  • CVE-2026-25038: The organization label read endpoints did not enforce organization visibility, leaking private organization labels to non-members.

The much larger batch of advisories fixed in the Gitea 1.27 series is not part of the 26.4.x line. Those CVEs are listed in our Gitea Enterprise 27.3.0 and Gitea Enterprise 27.3.1 posts, and we recommend planning an upgrade to 27.3.1.

How to install or update

Download our pre-built binaries from the Gitea Enterprise downloads page — make sure to select the version compatible with your platform. For a step-by-step guide on installation or upgrades, check out our installation documentation

Changelog

26.4.9 - 2026-09-01

  • BugFixes
    • Scale LDAP user-group sync to large directories
    • Fix paths-filter in Gitea workflows
    • Backport #38992: avoid enumerating every public repository in issue search

26.4.8 - 2026-08-21

  • Features
    • Allow * in the LDAP group filter

26.4.7 - 2026-08-15

  • Features
    • Pre-register a builtin OAuth2 application for the official Gitea mobile app
  • BugFixes
    • Refactor git patch apply
    • Fix orgmode render include path
    • Fix ssh test
    • Order the sign-in page's OAuth2 providers deterministically

26.4.6 - 2026-08-12

  • BugFixes
    • Normalize auth info before linking an account automatically
    • Add sign_in_failed audit log when login is prohibited

26.4.5 - 2026-08-10

  • Features
    • Complete repository-scoped DevOps dashboard filters
    • Auto activate an inactive account after account linking
    • Record files for push/pull audit logs
    • Add audit log for downloading a directory

This release is built on Gitea v1.26.4, unchanged since Gitea Enterprise 26.4.0.