{"id":"GO-2026-6656","summary":"gitea-runner: workflow container.options passes host namespaces and capability flags to job container when privileged mode is disabled in gitea.com/gitea/runner","details":"gitea-runner: workflow container.options passes host namespaces and capability flags to job container when privileged mode is disabled in gitea.com/gitea/runner","aliases":["CVE-2026-73802","GHSA-x4q3-gcj3-m6cf"],"modified":"2026-10-07T17:45:12.474497003Z","published":"2026-10-07T14:10:14Z","database_specific":{"review_status":"UNREVIEWED","url":"https://pkg.go.dev/vuln/GO-2026-6656"},"references":[{"type":"ADVISORY","url":"https://github.com/go-gitea/gitea/security/advisories/GHSA-x4q3-gcj3-m6cf"},{"type":"WEB","url":"https://gitea.com/gitea/runner/pulls/1058"},{"type":"WEB","url":"https://gitea.com/gitea/runner/releases/tag/v3.0.0"}],"affected":[{"package":{"name":"gitea.com/gitea/runner","ecosystem":"Go","purl":"pkg:golang/gitea.com/gitea/runner"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.0.9-0.20260731160927-34bfa1915022"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-6656.json"}}],"schema_version":"1.9.0"}