CVE-2026-103670
N/A
N/A
Summary
When a Gitea Actions run was inserted, older runs in the same workflow-level concurrency group were cancelled without checking whether the new run still needed approval. Because fork pull request runs are inserted under the base repository, a user who can open a pull request from a fork could cancel trusted in-progress runs that share a concurrency group with cancel-in-progress enabled, without approval and without running any code. On self-hosted runners this can interrupt deployments and leave partial state behind.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Gitea | Gitea | 0 <= 1.27.3 | affected |
Weaknesses
References
- https://github.com/go-gitea/gitea/security/advisories/GHSA-4j4g-m7mr-hp5j
- https://github.com/go-gitea/gitea/pull/39399
- https://blog.gitea.com/release-of-28.0.0/
- https://github.com/go-gitea/gitea/releases/tag/v28.0.0
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.