Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-73802: Gitea Runner may grant jobs extra system rights
CVE-2026-73802 · published 2 days ago
Summary
The Gitea Runner can unintentionally give a job container access to host system features and extra capabilities, even when privileged mode is turned off. This could let a malicious job affect the host server or other containers. Update the runner to the latest version or disable the risky container options until a fix is applied.
What to do
- Update gitea.com gitea to version 1.0.9-0.20260731160927-34bfa1915022.
- Update gitea gitea.com/gitea/runner to version 1.0.9-0.20260731160927-34bfa1915022.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| go | gitea.com | gitea |
< 1.0.9-0.20260731160927-34bfa1915022 Fix: upgrade to 1.0.9-0.20260731160927-34bfa1915022
|
| Go | gitea | gitea.com/gitea/runner |
< 1.0.9-0.20260731160927-34bfa1915022 Fix: upgrade to 1.0.9-0.20260731160927-34bfa1915022
|
Original advisory text
gitea-runner: workflow container.options passes host namespaces and capability flags to job container when privileged mode is disabled
gitea-runner: workflow container.options passes host namespaces and capability flags to job container when privileged mode is disabled in gitea.com/gitea/runner
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit (estimated)
- Gives an attacker full control (estimated)
Type
CWE-269Improper Privilege Management
Timeline
Published7 Oct 2026
Updated9 Oct 2026
First seen2 Oct 2026
Track software like this
Free during beta