Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-73802: Gitea Runner may grant jobs extra system rights

CVE-2026-73802 · published 2 days ago
Summary

The Gitea Runner can unintentionally give a job container access to host system features and extra capabilities, even when privileged mode is turned off. This could let a malicious job affect the host server or other containers. Update the runner to the latest version or disable the risky container options until a fix is applied.

What to do
  • Update gitea.com gitea to version 1.0.9-0.20260731160927-34bfa1915022.
  • Update gitea gitea.com/gitea/runner to version 1.0.9-0.20260731160927-34bfa1915022.
Affected software
Ecosystem VendorProductAffected versions
go gitea.com gitea < 1.0.9-0.20260731160927-34bfa1915022
Fix: upgrade to 1.0.9-0.20260731160927-34bfa1915022
Go gitea gitea.com/gitea/runner < 1.0.9-0.20260731160927-34bfa1915022
Fix: upgrade to 1.0.9-0.20260731160927-34bfa1915022
Original advisory text
gitea-runner: workflow container.options passes host namespaces and capability flags to job container when privileged mode is disabled
gitea-runner: workflow container.options passes host namespaces and capability flags to job container when privileged mode is disabled in gitea.com/gitea/runner
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit (estimated)
  • Gives an attacker full control (estimated)
Severity
9.9 Critical
Type
CWE-269Improper Privilege Management
Timeline
Published7 Oct 2026
Updated9 Oct 2026
First seen2 Oct 2026
Sources
GO-2026-6656 · OSV
Track software like this
Free during beta