PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-104626 Gitea CVE debrief

A Gitea vulnerability allows a user who can open a fork pull request to revive a workflow job through later approval. The issue arises when a user places workflow content with a shared run-level concurrency group into a Gitea Actions run awaiting approval. If a later run in that group cancels the blocked job, the run becomes terminal while still marked as needing approval. Upon later approval by a maintainer, Gitea passes the already-cancelled job through concurrency preparation, sets it to waiting, and makes it claimable by a matching runner, executing fork-controlled workflow code. This requires the maintainer's later approval action, Actions to be enabled, and a runner that accepts the repository's jobs.

Vendor
Gitea
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-06
Original CVE updated
2026-10-07
Advisory published
2026-10-06
Advisory updated
2026-10-07

Who should care

Gitea administrators and users who enable Actions and allow fork pull requests should assess their exposure to this vulnerability. They should verify their workflow approval processes and concurrency group usage to prevent exploitation.

Why it matters

Defenders should care about CVE-2026-104626 because it allows for the execution of fork-controlled workflow code in Gitea deployments. This requires verification of exposure in Gitea deployments where Actions are enabled and fork pull requests can be opened. The vulnerability's impact is supported by the official CVE Program record and NVD vulnerability detail. However, the exact scope of affected versions and remediation steps require further verification from official sources.

  • Execution of fork-controlled workflow code
  • Potential for unauthorized workflow job revival
  • Need for verification of Gitea deployments and workflow configurations
  • Importance of securing workflow approval processes

Technical summary

The vulnerability arises from Gitea's handling of fork pull requests and workflow jobs. A user can place workflow content with a shared run-level concurrency group into a Gitea Actions run awaiting approval. If a later run in that group cancels the blocked job, the run becomes terminal while still marked as needing approval. Upon later approval by a maintainer, Gitea passes the already-cancelled job through concurrency preparation, sets it to waiting, and makes it claimable by a matching runner, executing fork-controlled workflow code.

Defensive priority

Defenders should prioritize verifying exposure in Gitea deployments where Actions are enabled and fork pull requests can be opened. They should assess the use of concurrency groups in workflows and ensure that workflow approval processes are properly secured.

Recommended defensive actions

  • Verify Gitea deployments for exposure to fork pull requests and Actions enabled
  • Assess and secure workflow approval processes
  • Review concurrency group usage in workflows
  • Update to version 28.0.0 or later
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Evidence notes

The CVE Program record and NVD vulnerability detail provide official information on the vulnerability. The source item and supplemental sources offer additional context on the issue and potential mitigations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-104626 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-104626

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-104626 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104626

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Gitea fork workflow job revival through later approval

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/104xxx/CVE-2026-104626.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/go-gitea/gitea/security/advisories/GHSA-93pj-3x56-5gc2

    Supplemental source - vendor-advisory

  • Source reference

    Unverified legacy reference

    URL: https://github.com/go-gitea/gitea/pull/39399

    Supplemental source - patch

  • Source reference

    Unverified legacy reference

    URL: https://blog.gitea.com/release-of-28.0.0/

    Supplemental source - release-notes

  • Source reference

    Unverified legacy reference

    URL: https://github.com/go-gitea/gitea/releases/tag/v28.0.0

    Supplemental source - release-notes

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.