CRITICAL 9.9 GitHub

CVE-2026-73802

gitea-runner: workflow container.options passes host namespaces and capability flags to job container when privileged mode is disabled

### Summary act_runner appends workflow-controlled `jobs.<job>.container.options` directly to the Docker HostConfig for the job container. When runner privileged mode is disabled, only `Privileged` is forced false. Host namespace flags, capability expansion, and security profile overrides from workflow YAML are preserved in the final HostConfig. A workflow author can enter host PID/IPC namespaces and execute commands on the runner host as root. ### Details Source-to-sink path in act_runner

Affected Products

References

Published: 2026-10-02 · Source: GitHub · Feed updated: 2026-10-03
This critical severity vulnerability with a CVSS score of 9.9 was published on 2026-10-02 via GitHub. Affected: go/gitea.com/gitea/runner < 1.0.9-0.20260731160927-34bfa1915022.

Risk Timeline

CVE Disclosed2026-10-02 · 0 days ago

Remediation Resources

vulnfeed aggregates 9972 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.