CVE-2026-32946Disclosure(stepsecurity / harden-runner)

LOWCVSS 2.7 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch stepsecurity harden-runner systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. In versions 2.15.1 and below, the Harden-Runner that allows bypass of the egress-policy: block network restriction using DNS queries over TCP. Egress policies are enforced on GitHub runners by filtering outbound connections at the network layer. When egress-policy: block is enabled with a restrictive allowed-endpoints list (e.g., only github.com:443), all non-compliant traffic should be denied. However, DNS queries over TCP, commonly used for large responses or fallback from UDP, are not adequately restricted. Tools like dig can explicitly initiate TCP-based DNS queries (+tcp flag) without being blocked. This vulnerability requires the attacker to already have code execution capabilities within the GitHub Actions workflow. The issue has been fixed in version 2.16.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-693CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • harden-runner

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-20); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Products
harden-runner

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-18: 1Mentions · 2026-03-20: 2Mentions · 2026-03-24: 1Patch / Workaround · 2026-03-18: 1Technical Details · 2026-03-20: 1Technical Details · 2026-03-24: 103-1803-2003-24
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-181
Patch1
2026-03-202
Disclosure2
2026-03-241
Disclosure1
Full discourse4 posts
  • Devansh (⚡, 🥷)@0xAsm0d3us
    Patch

    Vulnerabilities I reported to Harden Runner, have now been assigned CVEs and fixed in the latest version. - CVE-2026-32947 - CVE-2026-32946 https://t.co/ZwP2WLZCGl

    Post summary

    Two Harden Runner vulnerabilities (CVE-2026-32947 and CVE-2026-32946) have been assigned CVEs and patched in the latest release.

    1103782.5K
    16.8K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32946 Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. In versions 2.15.1 and below, the Harden-Runner that allows bypass of the e… https://www.cve.org/CVERecord?id=CVE-2026-32946

    Post summary

    The excerpt merely cites CVE‑2026‑32946 and notes a bypass in Harden‑Runner, but offers no PoC, exploit details, patches, or confirmation of active exploitation.

    10010119
    56.8K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 Harden-Runner, Egress Policy Bypass, #CVE-2026-32946 (Medium) https://dailycve.com/harden-runner-egress-policy-bypass-cve-2026-32946-medium/

    Post summary

    A Medium severity CVE-2026-32946 is disclosed as an Egress Policy Bypass for Harden-Runner, but the text lacks PoC, exploit, patch, or active exploitation details.

    0000024
    173 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-32946 - Egress Policy Bypass via DNS over TCP in Harden-Runner (Community Tier) Intel Report: https://ift.tt/eKWaF8g

    Post summary

    The message announces the CVE-2026-32946 vulnerability—an egress policy bypass via DNS over TCP—providing a link to an intel report but no PoC, exploit, or patch details.

    0000046
    334 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appstepsecurityharden-runner---

Explore more