Security Advisory

CVE-2026-27780

9.8
CRITICAL

Vulnerability Description

Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowing oversized input to bypass branch-protection checks.
Published Date July 3, 2026
Official Source NIST NVD Advisory