UNKNOWN NVD
CVE-2026-103670
When a Gitea Actions run was inserted, older runs in the same workflow-level concurrency group were cancelled without checking whether the new run still needed
When a Gitea Actions run was inserted, older runs in the same workflow-level concurrency group were cancelled without checking whether the new run still needed approval. Because fork pull request runs are inserted under the base repository, a user who can open a pull request from a fork could cancel trusted in-progress runs that share a concurrency group with `cancel-in-progress` enabled, without approval and without running any code. On self-hosted runners this can interrupt deployments and leave partial state behind.
References
- https://blog.gitea.com/release-of-28.0.0/
- https://github.com/go-gitea/gitea/pull/39399
- https://github.com/go-gitea/gitea/releases/tag/v28.0.0
- https://github.com/go-gitea/gitea/security/advisories/GHSA-4j4g-m7mr-hp5j
This unknown severity vulnerability was published on 2026-10-06 via NVD.
vulnfeed aggregates 9512 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.