PT-2026-55605 · Gitea · Gitea

·

CVE-2026-27780

·

Published

2026-07-03

·

Updated

2026-09-10

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Gitea versions prior to 1.26.0
Description The software does not fail closed when encountering bufio.Scanner errors during the processing of pre-receive hook input. This behavior allows oversized input to bypass branch-protection checks.
Recommendations Update Gitea to version 1.26.0 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27780
GHSA-VHQ7-FWWH-7HJF
GO-2026-6346

Affected Products

Gitea