CVE-2026-103670

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

When a Gitea Actions run was inserted, older runs in the same workflow-level concurrency group were cancelled without checking whether the new run still needed approval. Because fork pull request runs are inserted under the base repository, a user who can open a pull request from a fork could cancel trusted in-progress runs that share a concurrency group with `cancel-in-progress` enabled, without approval and without running any code. On self-hosted runners this can interrupt deployments and leave partial state behind.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-667

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-08: 110-08
Referenced assets1 URL
By indicator
Full discourse1 post
  • zoomeyebot@zoomeyebot

    🚨 Gitea 28.1.0 Fixes an Actions Approval Bypass That Let Unapproved Fork Workflows Reach Runners Critical Vulnerability Alert! Gitea is affected by CVE-2026-103670. 🔍 Identify Targets via ZoomEye: Search Dork: app="Gitea" Exposure: 116.4k instances identified globally. ZoomEye Search Link: 👉 https://www.zoomeye.ai/searchResult?q=YXBwPSJHaXRlYSI%3D #Infosec #CyberSecurity #ZoomEye

    0000028
    25 followersView on X

Explore more