Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104632— Gitea fork workflow approval bypass through cancel and rerun

Quick assessment

Affected
Gitea Gitea
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Gitea Actions 会阻止首次通过 fork 的拉取请求(pull request)的Contributor触发的workflow作业执行,直到有维护者批准该流程。然而,重跑(rerun)路径仅要求任务运行结束并构建新尝试的作业,而未考虑待审批状态。因此,当具有Actions写入权限的用户取消一个等待批准的运行并重新运行它时,新创建的作业状态被设为“等待”而非“被阻止”,尽管该运行仍记录需要批准。取消并重新运行过时的fork检查是常规操作,不涉及审批控制机制。因此,在启用了Actions且注册了匹配运行器(

AI Predicted 5.9 Difficulty: Trivial

Possible ATT&CK Techniques 1 AI

T1059 · Command and Scripting Interpreter

Affected Version Matrix 1

VendorProduct Version RangeStatus
Gitea Gitea ≤ 1.27.3 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104632

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Gitea fork workflow approval bypass through cancel and rerun
Source: CVE Program / CVE List V5
Vulnerability Description
Gitea Actions blocks the jobs of workflow runs from first-time fork pull request contributors until a maintainer approves the run. The rerun path only required a run to be finished and built the new attempt's jobs without considering the pending approval, so when a user with Actions write access cancelled a run that was awaiting approval and then re-ran it, the new jobs were created as waiting rather than blocked while the run still recorded that approval was required. Cancelling and re-running stale fork checks is a routine action that does not involve the approval control, so where Actions is enabled and a matching runner is registered, workflow code taken from the fork pull request head could run on the repository's runners without an explicit approval.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Gitea Gitea 0 ~ 1.27.3 -

II. Public POCs for CVE-2026-104632

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104632

请登录查看更多情报信息。

Other References for CVE-2026-104632 (4)

Same Patch Batch · Gitea · 2026-10-06 · 21 CVEs total

CVE-2026-104636 Gitea SSRF through Git HTTP redirects in mirrors and fetches
CVE-2026-73278 Gitea WebAuthn bypass during OAuth and OIDC sign-in
CVE-2026-79960 Gitea deploy key pushes acting as the repository owner
CVE-2026-70357 Gitea repository migration SSRF through DNS rebinding
CVE-2026-96580 Gitea Actions memory exhaustion through large static matrices
CVE-2026-96589 Gitea private repository access retained after rejected transfer
CVE-2026-96400 Gitea migration SSRF to reserved addresses through ALLOWED_DOMAINS
CVE-2026-96399 Gitea denial of service through external issue tracker patterns
CVE-2026-96404 Gitea installer authentication bypass for existing accounts
CVE-2026-104626 Gitea fork workflow job revival through later approval
CVE-2026-94205 Gitea fork workflow approval bypass through maintainer-triggered events
CVE-2026-101027 Gitea migration SSRF through ALLOWED_DOMAINS address check bypass
CVE-2026-101029 Gitea migration and pull mirror SSRF through multi-answer DNS
CVE-2026-95106 Gitea review and execution mismatch through duplicate tree entries
CVE-2026-95112 Gitea issue reference parsing CPU exhaustion
CVE-2026-89430 Gitea push mirror SSRF and forced writes to internal Git hosts
CVE-2026-103504 Gitea API team demotion not applied to unit permissions
CVE-2026-103667 Gitea container registry stored XSS through blob media type
CVE-2026-103059 Gitea built-in SSH server authentication bypass through key case folding
CVE-2026-103670 Gitea trusted workflow cancellation by unapproved fork runs

IV. Related Vulnerabilities

V. Comments for CVE-2026-104632

No comments yet


Leave a comment