CVE-2026-27780: Gitea pre-receive hook scanner errors allow branch-protection bypass
(updated )
Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowing oversized input to bypass branch-protection checks.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-27780 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →