Critical severity9.8NVD Advisory· Published Jul 3, 2026· Updated Jul 6, 2026
CVE-2026-27780
CVE-2026-27780
Description
Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowing oversized input to bypass branch-protection checks.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
code.gitea.io/giteaGo | < 1.26.0 | 1.26.0 |
Affected products
1Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-vhq7-fwwh-7hjfghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-27780ghsaADVISORY
- blog.gitea.com/release-of-1.26.0ghsaWEB
- github.com/go-gitea/gitea/commit/c453d09c36fad094405314dba2f370434b200711ghsaWEB
- github.com/go-gitea/gitea/pull/36963nvdWEB
- github.com/go-gitea/gitea/releases/tag/v1.26.0nvdWEB
- blog.gitea.com/release-of-1.26.0/nvd
News mentions
0No linked articles in our index yet.