CVE-2026-27780: Gitea pre-receive hook scanner errors allow branch-protection bypass

Severity: Critical

CVSS Score: 9.8

Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowing oversized input to bypass branch-protection checks.