Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-264 CWE-284 |
Tue, 06 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Gitea Actions blocks the jobs of workflow runs from first-time fork pull request contributors until a maintainer approves the run. The rerun path only required a run to be finished and built the new attempt's jobs without considering the pending approval, so when a user with Actions write access cancelled a run that was awaiting approval and then re-ran it, the new jobs were created as waiting rather than blocked while the run still recorded that approval was required. Cancelling and re-running stale fork checks is a routine action that does not involve the approval control, so where Actions is enabled and a matching runner is registered, workflow code taken from the fork pull request head could run on the repository's runners without an explicit approval. | |
| Title | Gitea fork workflow approval bypass through cancel and rerun | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Gitea
Published:
Updated: 2026-10-06T19:22:04.308Z
Reserved: 2026-10-04T21:57:35.543Z
Link: CVE-2026-104632
No data.
Status : Received
Published: 2026-10-06T20:17:15.237
Modified: 2026-10-06T20:17:15.237
Link: CVE-2026-104632
No data.
OpenCVE Enrichment
Updated: 2026-10-06T21:15:06Z