CVE-2026-104632: Gitea fork workflow approval bypass through cancel and rerun

Published Oct 6, 2026
·
Updated

Gitea Actions blocks the jobs of workflow runs from first-time fork pull request contributors until a maintainer approves the run. The rerun path only required a run to be finished and built the new attempt's jobs without considering the pending approval, so when a user with Actions write access cancelled a run that was awaiting approval and then re-ran it, the new jobs were created as waiting rather than blocked while the run still recorded that approval was required. Cancelling and re-running stale fork checks is a routine action that does not involve the approval control, so where Actions is enabled and a matching runner is registered, workflow code taken from the fork pull request head could run on the repository's runners without an explicit approval.

Affected Software

1 affected component
Gitea Gitea

Event History

Oct 6, 2026
CVE Published
via MITRE·07:22 PM
Data Sourced
via MITRE·07:22 PM
Description
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can trigger the bypass?

A user with Actions write access can cancel a fork pull request workflow run that is awaiting approval and then re-run it. The issue applies to first-time fork pull request contributors whose workflow jobs would normally be blocked pending maintainer approval.

2

What conditions are required for fork code to execute?

Actions must be enabled and a matching runner must be registered. The affected run must be a finished run that was awaiting approval, and the user must be able to cancel and re-run it.

3

What is the security impact of a successful bypass?

Workflow code from the fork pull request head can run on the repository's runners without explicit maintainer approval. This defeats the approval gate intended to prevent untrusted first-time fork contributor workflows from executing.

4

What can be done while a fix is not available?

Avoid cancelling and re-running workflow checks for first-time fork pull requests that are awaiting approval. Review completed or rerun fork pull request workflows for runs whose approval was still recorded as required but whose jobs were created in a waiting state.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203