Gitea fork workflow job revival through later approval
Summary
| CVE | CVE-2026-104626 |
|---|---|
| State | PUBLISHED |
| Assigner | Gitea |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-10-06 20:17:15 UTC |
| Updated | 2026-10-06 20:17:15 UTC |
| Description | A user who can open a fork pull request can place workflow content with a shared run-level concurrency group into a Gitea Actions run that is awaiting approval. When a later run in that group cancels the blocked job, the run becomes terminal while still marked as needing approval. If a maintainer later approves the run, Gitea passed the already-cancelled job back through concurrency preparation, set it to waiting, and made it claimable by a matching runner, executing fork-controlled workflow code. Exploitation requires the maintainer's later approval action, Actions to be enabled, and a runner that accepts the repository's jobs. |
Risk And Classification
Problem Types: CWE-841 | CWE-841 CWE-841: Improper Enforcement of Behavioral Workflow
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/go-gitea/gitea/releases/tag/v28.0.0 | 88ee5874-cf24-4952-aea0-31affedb7ff2 | github.com | |
| blog.gitea.com/release-of-28.0.0 | 88ee5874-cf24-4952-aea0-31affedb7ff2 | blog.gitea.com | |
| github.com/go-gitea/gitea/pull/39399 | 88ee5874-cf24-4952-aea0-31affedb7ff2 | github.com | |
| github.com/go-gitea/gitea/security/advisories/GHSA-93pj-3x56-5gc2 | 88ee5874-cf24-4952-aea0-31affedb7ff2 | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: https://github.com/opensec-intelligence (en)
CNA: https://github.com/mayank-jangid-moon (en)
CNA: https://github.com/Kushalkhemka (en)
CNA: https://github.com/skigeek16 (en)
CNA: https://github.com/nithissh7 (en)
CNA: https://github.com/kewmine (en)
CNA: https://github.com/bircni (en)
CNA: https://github.com/silverwind (en)
There are currently no legacy QID mappings associated with this CVE.