GO · JULY 2026 · EARLY WARNING

Gitea Versions Before 1.26.0: Branch-Protection Bypass Vulnerability

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
HIGH
Affected component
gitea (go)
Affected versions
< 1.26.0
Patched version
1.26.0
GHSA-VHQ7-FWWH-7HJF

An early warning has been issued for a vulnerability in Gitea versions before 1.26.0 that may allow branch-protection bypass due to scanner errors. Users of affected versions should assess their exposure and consider upgrading.

What happened

An early warning has been issued regarding a vulnerability in Gitea versions before 1.26.0. This vulnerability, tracked as GHSA-VHQ7-FWWH-7HJF, involves the failure to handle bufio.Scanner errors during pre-receive hook input processing. As a result, oversized input may bypass branch-protection checks. This issue has a high severity rating and is under investigation. It is not yet confirmed to have been exploited in the wild.

The vulnerability affects the gitea (go) component in versions before 1.26.0. The recommended action is to upgrade to Gitea version 1.26.0 or later to mitigate the risk. Users should review their current Gitea version and assess whether they are running an affected version.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If gitea is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are affected if you are using Gitea versions before 1.26.0.

What should I do right now?

Identify your current Gitea version and upgrade to version 1.26.0 or later if you are using an affected version.

Is this vulnerability confirmed?

No, this is an early warning and the vulnerability is under investigation.

Has this been exploited in the wild?

No, there is no evidence that this vulnerability has been exploited in the wild.

Sources

Join the 0Day waitlist →

← Back to all threats