Gitea Actions 在判断来自 Fork 的拉取请求(Pull Request)运行是否需要审批时,依据的是触发该事件的用户,而非拉取请求的作者。在常规问题分类(triage)过程中,由维护者触发的 活动(例如添加标签),会直接创建运行任务,而无需经过审批;然而,工作流的定义仍取自 Fork 仓库的 HEAD 分支。当启用了 Gitea Actions 且已注册匹配的运行器(runner)时,Fork 控制的工作流代码便可在基础仓库(base repository)的运行器上执行,而无需明确授权。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-104632 | Gitea fork workflow approval bypass through cancel and rerun | |
| CVE-2026-73278 | Gitea WebAuthn bypass during OAuth and OIDC sign-in | |
| CVE-2026-79960 | Gitea deploy key pushes acting as the repository owner | |
| CVE-2026-70357 | Gitea repository migration SSRF through DNS rebinding | |
| CVE-2026-96580 | Gitea Actions memory exhaustion through large static matrices | |
| CVE-2026-96589 | Gitea private repository access retained after rejected transfer | |
| CVE-2026-96400 | Gitea migration SSRF to reserved addresses through ALLOWED_DOMAINS | |
| CVE-2026-96399 | Gitea denial of service through external issue tracker patterns | |
| CVE-2026-96404 | Gitea installer authentication bypass for existing accounts | |
| CVE-2026-104626 | Gitea fork workflow job revival through later approval | |
| CVE-2026-103670 | Gitea trusted workflow cancellation by unapproved fork runs | |
| CVE-2026-104636 | Gitea SSRF through Git HTTP redirects in mirrors and fetches | |
| CVE-2026-101027 | Gitea migration SSRF through ALLOWED_DOMAINS address check bypass | |
| CVE-2026-101029 | Gitea migration and pull mirror SSRF through multi-answer DNS | |
| CVE-2026-95106 | Gitea review and execution mismatch through duplicate tree entries | |
| CVE-2026-95112 | Gitea issue reference parsing CPU exhaustion | |
| CVE-2026-89430 | Gitea push mirror SSRF and forced writes to internal Git hosts | |
| CVE-2026-103504 | Gitea API team demotion not applied to unit permissions | |
| CVE-2026-103667 | Gitea container registry stored XSS through blob media type | |
| CVE-2026-103059 | Gitea built-in SSH server authentication bypass through key case folding |
No comments yet