CVE-2026-32947Disclosure(stepsecurity / harden-runner)

LOWCVSS 4.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch stepsecurity harden-runner systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. In versions 2.15.1 and below, a DNS over HTTPS (DoH) vulnerability allows attackers to bypass egress-policy: block network restrictions by tunneling exfiltrated data through permitted HTTPS endpoints like dns.google. The attack works by encoding sensitive data (e.g., the runner's hostname) as subdomains in DoH queries, which appear as legitimate HTTPS traffic to Harden-Runner's domain-based filtering but are ultimately forwarded to an attacker-controlled domain. This effectively enables data exfiltration without directly connecting to any blocked destination. Exploitation requires the attacker to already have code execution within the GitHub Actions workflow. The issue was fixed in version 2.16.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-693CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • harden-runner

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-03-18); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
harden-runner

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-18: 1Mentions · 2026-03-20: 1Mentions · 2026-03-24: 1Patch / Workaround · 2026-03-18: 1Technical Details · 2026-03-20: 1Technical Details · 2026-03-24: 103-1803-2003-24
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-181
Patch1
2026-03-201
Disclosure1
2026-03-241
Disclosure1
Full discourse3 posts
  • Devansh (⚡, 🥷)@0xAsm0d3us
    Patch

    Vulnerabilities I reported to Harden Runner, have now been assigned CVEs and fixed in the latest version. - CVE-2026-32947 - CVE-2026-32946 https://t.co/ZwP2WLZCGl

    Post summary

    The author reports that the vulnerabilities reported to Harden Runner were assigned CVEs and have been addressed with a fix in the latest release.

    1103782.5K
    16.8K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32947 Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. In versions 2.15.1 and below, a DNS over HTTPS (DoH) vulnerability allows a… https://www.cve.org/CVERecord?id=CVE-2026-32947

    Post summary

    The post briefly announces a DNS over HTTPS (DoH) vulnerability (CVE‑2026‑32947) affecting Harden‑Runner versions 2.15.1 and below, without mentioning exploits, patches, or PoC details.

    10010121
    56.8K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 Harden-Runner, DNS over HTTPS Vulnerability, #CVE-2026-32947 (Medium) https://dailycve.com/harden-runner-dns-over-https-vulnerability-cve-2026-32947-medium/

    Post summary

    This post announces the CVE‑2026‑32947 vulnerability in Harden‑Runner related to DNS over HTTPS, rated medium severity, but offers no further details on PoC, exploitation, or patches.

    0000037
    173 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appstepsecurityharden-runner---

Explore more