CRITICAL 9.9 GitHub
CVE-2026-73802
gitea-runner: workflow container.options passes host namespaces and capability flags to job container when privileged mode is disabled
### Summary
act_runner appends workflow-controlled `jobs.<job>.container.options` directly
to the Docker HostConfig for the job container. When runner privileged mode is
disabled, only `Privileged` is forced false. Host namespace flags, capability
expansion, and security profile overrides from workflow YAML are preserved in
the final HostConfig. A workflow author can enter host PID/IPC namespaces and
execute commands on the runner host as root.
### Details
Source-to-sink path in act_runner
Affected Products
- go/gitea.com/gitea/runner < 1.0.9-0.20260731160927-34bfa1915022
References
- https://github.com/advisories/GHSA-x4q3-gcj3-m6cf
- https://github.com/go-gitea/gitea/security/advisories/GHSA-x4q3-gcj3-m6cf
- https://gitea.com/gitea/runner/pulls/1058
- https://gitea.com/gitea/runner/releases/tag/v3.0.0
This critical severity vulnerability with a CVSS score of 9.9 was published on 2026-10-02 via GitHub. Affected: go/gitea.com/gitea/runner < 1.0.9-0.20260731160927-34bfa1915022.
Risk Timeline
CVE Disclosed2026-10-02 · 0 days ago
Remediation Resources
vulnfeed aggregates 9972 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.