CVE-2026-27780
published 2026-07-03CVE-2026-27780: Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowing oversized input to bypass…
PriorityP354critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.47%
39.1th percentile
Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowing oversized input to bypass branch-protection checks.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gitea | gitea_open_source_git_server | < 1.26.0 | 1.26.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Gitea up to 1.25.x authorization
vuldb·2026-07-04
CVE-2026-27780 [LOW] Gitea up to 1.25.x authorization
A vulnerability marked as problematic has been reported in Gitea up to 1.25.x. This impacts an unknown function. Performing a manipulation results in incorrect authorization.
This vulnerability is known as CVE-2026-27780. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
GHSA
Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowing oversized input to bypass branch-protection checks.
ghsa_unreviewed·2026-07-03
CVE-2026-27780 CWE-863 Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowing oversized input to bypass branch-protection checks.
Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowing oversized input to bypass branch-protection checks.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-03
Published