能够发起从分支拉取请求(fork pull request)的用户,可以将包含共享运行级别并发组的 workflow 内容放入一个等待审批的 Gitea Actions 运行任务中。当该并发组中的后续运行任务取消被阻塞的作业时,该运行任务虽然仍处于“需要审批”状态,但其状态已变为终止(terminal)。如果维护者随后批准了该运行任务,Gitea 会将已取消的作业重新通过并发准备阶段,将其状态设置为等待,并使其可被匹配的 runner 领取,从而执行由 fork 控制的 workflow 代码。 利用此漏洞需满足以
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-104636 | Gitea SSRF through Git HTTP redirects in mirrors and fetches | |
| CVE-2026-73278 | Gitea WebAuthn bypass during OAuth and OIDC sign-in | |
| CVE-2026-79960 | Gitea deploy key pushes acting as the repository owner | |
| CVE-2026-70357 | Gitea repository migration SSRF through DNS rebinding | |
| CVE-2026-96580 | Gitea Actions memory exhaustion through large static matrices | |
| CVE-2026-96589 | Gitea private repository access retained after rejected transfer | |
| CVE-2026-96400 | Gitea migration SSRF to reserved addresses through ALLOWED_DOMAINS | |
| CVE-2026-96399 | Gitea denial of service through external issue tracker patterns | |
| CVE-2026-96404 | Gitea installer authentication bypass for existing accounts | |
| CVE-2026-104632 | Gitea fork workflow approval bypass through cancel and rerun | |
| CVE-2026-94205 | Gitea fork workflow approval bypass through maintainer-triggered events | |
| CVE-2026-101027 | Gitea migration SSRF through ALLOWED_DOMAINS address check bypass | |
| CVE-2026-101029 | Gitea migration and pull mirror SSRF through multi-answer DNS | |
| CVE-2026-95106 | Gitea review and execution mismatch through duplicate tree entries | |
| CVE-2026-95112 | Gitea issue reference parsing CPU exhaustion | |
| CVE-2026-89430 | Gitea push mirror SSRF and forced writes to internal Git hosts | |
| CVE-2026-103504 | Gitea API team demotion not applied to unit permissions | |
| CVE-2026-103667 | Gitea container registry stored XSS through blob media type | |
| CVE-2026-103059 | Gitea built-in SSH server authentication bypass through key case folding | |
| CVE-2026-103670 | Gitea trusted workflow cancellation by unapproved fork runs |
No comments yet