CVE-2026-58053Disclosure

LOWCVSS 9.4 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with privileged: false, forces only the Privileged flag off while merging options such as --pid=host, --cap-add, and --security-opt unchanged. A user who can run a workflow on a Docker-backed runner can create a job container with host namespaces and broad capabilities and escape to the host as root despite privileged mode being disabled.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-06-28: 4Patch / Workaround · 2026-06-28: 1Technical Details · 2026-06-28: 306-28
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets3 URLs
Full discourse4 posts
  • VulDB 🛡@vuldb
    Disclosure

    A severe vulnerability was disclosed for Gitea act_runner (CVE-2026-58053) https://vuldb.com/vuln/374503

    Post summary

    The short announcement simply reveals the existence of CVE-2026-58053 and provides a link to a vulnerability database entry.

    00010128
    2.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-58053 Container Escape to Root in Gitea act_runner Docker Backend via U... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-58053 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The post merely references CVE-2026-58053 with a brief mention of a container‑escape vulnerability, providing no PoC, exploit code, patch information, or evidence of active exploitation.

    00010172
    4.1K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-58053 — CVSS 9.9/10 ██████████ Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/IZ1fBPE1iN

    Post summary

    CVE‑2026‑58053 is a critical flaw in Gitea’s act_runner Docker backend; a patch is available immediately.

    10000262
    62 followersView on X
  • ADK Cyber@ADKCyber
    Disclosure

    CVE-2026-58053 (CVSS 9.9) affects Gitea act_runner Docker backend. Organizations using self-hosted runners should review the advisory. via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability https://t.co/fvDg2ALVzR

    Post summary

    The tweet discloses a high‑severity CVE affecting Gitea’s act_runner Docker backend and recommends reviewing the advisory.

    0000064
    92 followersView on X

Explore more