PatchSiren cyber security CVE debrief
CVE-2026-104626 Gitea CVE debrief
A Gitea vulnerability allows a user who can open a fork pull request to revive a workflow job through later approval. The issue arises when a user places workflow content with a shared run-level concurrency group into a Gitea Actions run awaiting approval. If a later run in that group cancels the blocked job, the run becomes terminal while still marked as needing approval. Upon later approval by a maintainer, Gitea passes the already-cancelled job through concurrency preparation, sets it to waiting, and makes it claimable by a matching runner, executing fork-controlled workflow code. This requires the maintainer's later approval action, Actions to be enabled, and a runner that accepts the repository's jobs.
- Vendor
- Gitea
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-06
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-06
- Advisory updated
- 2026-10-07
Who should care
Gitea administrators and users who enable Actions and allow fork pull requests should assess their exposure to this vulnerability. They should verify their workflow approval processes and concurrency group usage to prevent exploitation.
Why it matters
Defenders should care about CVE-2026-104626 because it allows for the execution of fork-controlled workflow code in Gitea deployments. This requires verification of exposure in Gitea deployments where Actions are enabled and fork pull requests can be opened. The vulnerability's impact is supported by the official CVE Program record and NVD vulnerability detail. However, the exact scope of affected versions and remediation steps require further verification from official sources.
- Execution of fork-controlled workflow code
- Potential for unauthorized workflow job revival
- Need for verification of Gitea deployments and workflow configurations
- Importance of securing workflow approval processes
Technical summary
The vulnerability arises from Gitea's handling of fork pull requests and workflow jobs. A user can place workflow content with a shared run-level concurrency group into a Gitea Actions run awaiting approval. If a later run in that group cancels the blocked job, the run becomes terminal while still marked as needing approval. Upon later approval by a maintainer, Gitea passes the already-cancelled job through concurrency preparation, sets it to waiting, and makes it claimable by a matching runner, executing fork-controlled workflow code.
Defensive priority
Defenders should prioritize verifying exposure in Gitea deployments where Actions are enabled and fork pull requests can be opened. They should assess the use of concurrency groups in workflows and ensure that workflow approval processes are properly secured.
Recommended defensive actions
- Verify Gitea deployments for exposure to fork pull requests and Actions enabled
- Assess and secure workflow approval processes
- Review concurrency group usage in workflows
- Update to version 28.0.0 or later
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Evidence notes
The CVE Program record and NVD vulnerability detail provide official information on the vulnerability. The source item and supplemental sources offer additional context on the issue and potential mitigations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-104626 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-104626
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-104626 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104626
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Gitea fork workflow job revival through later approval
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/104xxx/CVE-2026-104626.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/go-gitea/gitea/security/advisories/GHSA-93pj-3x56-5gc2
Supplemental source - vendor-advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/go-gitea/gitea/pull/39399
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://blog.gitea.com/release-of-28.0.0/
Supplemental source - release-notes
-
Source reference
Unverified legacy reference
URL: https://github.com/go-gitea/gitea/releases/tag/v28.0.0
Supplemental source - release-notes
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.