Gitea Enterprise 26.4.9 is released

We are excited to announce the release of Gitea Enterprise 26.4.9! This release rolls up the 26.4.5, 26.4.6, 26.4.7, 26.4.8 and 26.4.9 patch releases. It completes the repository-scoped DevOps dashboard filters, extends audit logging to file-level push/pull activity and directory downloads, hardens account linking, and makes LDAP user-group synchronization work on large directories.
Audit & Compliance
- Push and pull audit records now list the files involved
- Downloading a directory is recorded in the audit log
- A
sign_in_failedaudit entry is written when a prohibited account attempts to sign in
Directory & Authentication
- LDAP group filters accept
* - LDAP user-group synchronization scales to large directories
- Authentication info is normalized before an account is linked automatically, and an inactive account is activated after a successful link
- The sign-in page lists OAuth2 providers in a deterministic order
Major Breaking changes
No breaking changes are introduced between 26.4.4 and 26.4.9. The embedded Gitea remains on v1.26.4, unchanged since Gitea Enterprise 26.4.0. As always, back up your database and repository storage before upgrading.
Major Highlights
🚀 Repository-scoped DevOps dashboard filters
The DevOps dashboard filters are now complete at repository scope, so a repository dashboard can be narrowed the same way instance-level and organization-level dashboards can. Metrics, time ranges and widget selection stay consistent across all three scopes.
🚀 File-level audit trail for push and pull
Push and pull audit records now capture the files that were transferred, and downloading a directory produces its own audit entry. Together with the sign_in_failed entry written when a prohibited account tries to sign in, this closes the remaining gaps auditors usually ask about when reviewing code-movement evidence.
🚀 Smoother — but still reviewed — account linking
When an existing user links an external identity, the authentication information is normalized first so the match is reliable, and an account that was left inactive by LDAP synchronization is activated once the link succeeds. This keeps the "new LDAP users start inactive" policy introduced in 26.4.4 while removing the manual step for users who prove their identity through a configured provider.
🚀 LDAP synchronization for large directories
LDAP user-group synchronization was reworked to scale to large directories instead of resolving group membership one entry at a time, and group filters may now contain *. Instances with tens of thousands of directory entries should see substantially shorter synchronization runs.
🚀 Built-in OAuth2 application for the Gitea mobile app
A built-in OAuth2 application for the official Gitea mobile app is now pre-registered, so administrators no longer need to create and distribute an application registration before their users can sign in from mobile.
Security
The 26.4.x line stays on Gitea v1.26.4, which contains the security fixes published for Gitea 1.26.3 and 1.26.4:
- CVE-2026-20896: The Docker images shipped a
REVERSE_PROXY_TRUSTED_PROXIES = *default, which let any source IP impersonate any user via theX-WEBAUTH-USERheader. - CVE-2026-22874: The default allow-list filter used by webhooks and migrations was too permissive, leaving an incomplete SSRF protection that could reach internal addresses.
- CVE-2026-27775: The pre-receive hook cached the first ref's permission result, letting a per-branch maintainer-edit grant escalate to full repository write.
- CVE-2026-24451: Fork synchronization could pull commits made after the parent repository was switched from public to private.
- CVE-2026-20779: TOTP passcodes were not strictly single-use across web login, password reset and the Basic-Auth OTP surface.
- CVE-2026-28740: Cross-repository LFS object reuse did not require Code-unit access, so a non-Code grant could authorize private source objects.
- CVE-2026-27761: The RSS/Atom feed endpoints did not enforce repository token scope, so a token without repository scope could read private repository commit data.
- CVE-2026-25038: The organization label read endpoints did not enforce organization visibility, leaking private organization labels to non-members.
The much larger batch of advisories fixed in the Gitea 1.27 series is not part of the 26.4.x line. Those CVEs are listed in our Gitea Enterprise 27.3.0 and Gitea Enterprise 27.3.1 posts, and we recommend planning an upgrade to 27.3.1.
How to install or update
Download our pre-built binaries from the Gitea Enterprise downloads page — make sure to select the version compatible with your platform. For a step-by-step guide on installation or upgrades, check out our installation documentation
Changelog
26.4.9 - 2026-09-01
- BugFixes
- Scale LDAP user-group sync to large directories
- Fix
paths-filterin Gitea workflows - Backport #38992: avoid enumerating every public repository in issue search
26.4.8 - 2026-08-21
- Features
- Allow
*in the LDAP group filter
- Allow
26.4.7 - 2026-08-15
- Features
- Pre-register a builtin OAuth2 application for the official Gitea mobile app
- BugFixes
- Refactor git patch apply
- Fix orgmode render include path
- Fix ssh test
- Order the sign-in page's OAuth2 providers deterministically
26.4.6 - 2026-08-12
- BugFixes
- Normalize auth info before linking an account automatically
- Add
sign_in_failedaudit log when login is prohibited
26.4.5 - 2026-08-10
- Features
- Complete repository-scoped DevOps dashboard filters
- Auto activate an inactive account after account linking
- Record files for push/pull audit logs
- Add audit log for downloading a directory
This release is built on Gitea v1.26.4, unchanged since Gitea Enterprise 26.4.0.