CVE-2026-103670
Gitea trusted workflow cancellation by unapproved fork runs
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
When a Gitea Actions run was inserted, older runs in the same workflow-level concurrency group were cancelled without checking whether the new run still needed approval. Because fork pull request runs are inserted under the base repository, a user who can open a pull request from a fork could cancel trusted in-progress runs that share a concurrency group with `cancel-in-progress` enabled, without approval and without running any code. On self-hosted runners this can interrupt deployments and leave partial state behind.
| Vendor | gitea |
| Product | gitea |
| Published | Oct 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for gitea gitea
Be the first to know when new unknown vulnerabilities affecting gitea gitea are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Gitea / Gitea
0 โค 1.27.3
References
Credits
๐ https://github.com/Pedromdsn https://github.com/bircni https://github.com/silverwind