← العودة للجدول
CVE-2026-73802
CVE-2026-73802 — gitea-runner: workflow container.options passes host namespaces and capability f
📅 2026-10-03
🔴 Critical 🔥 No GHSA Vulnerability Vulnerability CVSS 9.9

📋 الوصف الكامل

### Summary act_runner appends workflow-controlled `jobs..container.options` directly to the Docker HostConfig for the job container. When runner privileged mode is disabled, only `Privileged` is forced false. Host namespace flags, capability expansion, and security profile overrides from workflow YAML are preserved in the final HostConfig. A workflow author can enter host PID/IPC namespaces a

💻 الأنظمة المتأثرة

Ubuntu Linux | Docker

⚠️ نوع التهديد

Vulnerability

🔗 CVE ID

CVE-2026-73802

📡 المصدر

GHSA

✅ الحلول والتخفيف

Refer to CVE-2026-73802 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ← 🔍 Valters IT ←