Vulnerability Reportgitea/act_runner:0.5.0

gitea/act_runner:0.5gitea/act_runner:0.5.0
DIGESTsha256:9946000491cf19c3ed487c23e5da4f0c287010d791f495796c756e41e7a79cbe

Executive Summary

Threat Score
50/100CAUTION
Reputation
RELIABLE

This image carries significant risk; production deployment is highly discouraged without strict compensating controls. An attacker could exploit CVE-2026-45570 to execute arbitrary commands when the runner clones a malicious repository via SSH, or exploit CVE-2026-34040 to bypass authorization plugins if the Docker socket is accessible. Disabling SSH cloning or using only trusted repository sources would fully mitigate CVE-2026-45570. Note that CVE-2026-33747 requires a specially configured untrusted BuildKit frontend, which is not the default.

Vulnerabilities

Vulnerability Log

91 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-33747MEDIUM6.66
github.com/moby/buildkit
v0.13.2
fixed in 0.28.1
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-45570MEDIUM6.53
github.com/go-git/go-git/v5
v5.18.0
fixed in 5.19.1
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-45186MEDIUM6.38
libexpat
2.7.5-r0
fixed in 2.8.1-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-45022MEDIUM6.38
github.com/go-git/go-git/v5
v5.18.0
fixed in 5.19.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-39830MEDIUM6.38
golang.org/x/crypto
v0.48.0
fixed in 0.52.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-39836MEDIUM6.38
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-34182MEDIUM6.29
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-34182MEDIUM6.29
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42508MEDIUM6.29
golang.org/x/crypto
v0.48.0
fixed in 0.52.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34040MEDIUM6.24
github.com/docker/docker
v25.0.13+incompatible
fixed in 29.3.1
8.1%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2026-42306MEDIUM6.12
github.com/docker/docker
v25.0.13+incompatible
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-46595MEDIUM6.03
golang.org/x/crypto
v0.48.0
fixed in 0.52.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-39821MEDIUM5.58
golang.org/x/net
v0.50.0
fixed in 0.55.0
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-34181MEDIUM5.35
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42768MEDIUM5.35
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34181MEDIUM5.35
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42768MEDIUM5.35
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-33748MEDIUM5.1
github.com/moby/buildkit
v0.13.2
fixed in 0.28.1
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-39829MEDIUM5.1
golang.org/x/crypto
v0.48.0
fixed in 0.52.0
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-33814MEDIUM5.1
golang.org/x/net
v0.50.0
fixed in 0.53.0
0.6%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-33811MEDIUM5.1
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-33814MEDIUM5.1
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-42764MEDIUM5.02
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-42769MEDIUM5.02
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42770MEDIUM5.02
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-9076MEDIUM5.02
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42764MEDIUM5.02
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-42769MEDIUM5.02
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42770MEDIUM5.02
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-9076MEDIUM5.02
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-7383MEDIUM4.67
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-7383MEDIUM4.67
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-39826MEDIUM4.59
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM4.5
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42767MEDIUM4.5
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM4.5
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42767MEDIUM4.5
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-46598MEDIUM4.5
golang.org/x/crypto
v0.48.0
fixed in 0.52.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-27141MEDIUM4.5
golang.org/x/net
v0.50.0
fixed in 0.51.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-42507MEDIUM4.5
stdlib
v1.26.2
fixed in 1.25.11, 1.26.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34180MEDIUM4.25
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-34180MEDIUM4.25
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-41568LOW3.31
github.com/docker/docker
v25.0.13+incompatible
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-45446LOW3.15
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-41080LOW3.15
libexpat
2.7.5-r0
fixed in 2.8.1-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-45446LOW3.15
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-45447LOW2.92
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
2.3%
Low-Moderate Risk
Post-Exploit
CVE-2026-45447LOW2.92
libssl3
3.5.6-r0
fixed in 3.5.7-r0
2.3%
Low-Moderate Risk
Post-Exploit
CVE-2026-3783LOW2.91
libcurl
8.17.0-r1
fixed in 8.19.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-39828LOW2.69
golang.org/x/crypto
v0.48.0
fixed in 0.52.0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-33997LOW2.48
github.com/docker/docker
v25.0.13+incompatible
fixed in 29.3.1
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-15558LOW2.45
github.com/docker/cli
v25.0.7+incompatible
fixed in 29.2.0
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-14017LOW2.45
libcurl
8.17.0-r1
fixed in 8.19.0-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-34183LOW2.29
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-34183LOW2.29
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-27135LOW2.29
nghttp2-libs
1.68.0-r0
fixed in 1.68.1
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-29181LOW2.29
go.opentelemetry.io/otel
v1.40.0
fixed in 1.41.0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-39820LOW2.29
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-1965LOW2.08
libcurl
8.17.0-r1
fixed in 8.19.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-14819LOW2.08
libcurl
8.17.0-r1
fixed in 8.19.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-3784LOW1.99
libcurl
8.17.0-r1
fixed in 8.19.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-14524LOW1.99
libcurl
8.17.0-r1
fixed in 8.19.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-3805LOW1.93
libcurl
8.17.0-r1
fixed in 8.19.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-46680NONE0
github.com/containerd/containerd
v1.7.29
fixed in 1.7.32
Not Applicable
CVE-2026-53488NONE0
github.com/containerd/containerd
v1.7.29
fixed in 1.7.33
Not Applicable
CVE-2026-47262NONE0
github.com/containerd/containerd
v1.7.29
fixed in 1.7.33
Not Applicable
CVE-2026-41567NONE0
github.com/docker/docker
v25.0.13+incompatible
No fix yet
0.1%
Theoretical Threat
Not Applicable
CVE-2026-44973NONE0
github.com/go-git/go-billy/v5
v5.8.0
fixed in 5.9.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-44740NONE0
github.com/go-git/go-billy/v5
v5.8.0
fixed in 5.9.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-45571NONE0
github.com/go-git/go-git/v5
v5.18.0
fixed in 5.19.1
0.3%
Theoretical Threat
Not Applicable
GHSA-w5pp-99ch-qj29NONE0
github.com/go-git/go-git/v5
v5.18.0
fixed in 5.19.1
Not Applicable
CVE-2026-39827NONE0
golang.org/x/crypto
v0.48.0
fixed in 0.52.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-39835NONE0
golang.org/x/crypto
v0.48.0
fixed in 0.52.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-46597NONE0
golang.org/x/crypto
v0.48.0
fixed in 0.52.0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-39831NONE0
golang.org/x/crypto
v0.48.0
fixed in 0.52.0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-39832NONE0
golang.org/x/crypto
v0.48.0
fixed in 0.52.0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-39833NONE0
golang.org/x/crypto
v0.48.0
fixed in 0.52.0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-39834NONE0
golang.org/x/crypto
v0.48.0
fixed in 0.52.0
0.5%
Theoretical Threat
Not Applicable
CVE-2026-25680NONE0
golang.org/x/net
v0.50.0
fixed in 0.55.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-25681NONE0
golang.org/x/net
v0.50.0
fixed in 0.55.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-27136NONE0
golang.org/x/net
v0.50.0
fixed in 0.55.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-42502NONE0
golang.org/x/net
v0.50.0
fixed in 0.55.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-42506NONE0
golang.org/x/net
v0.50.0
fixed in 0.55.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-39824NONE0
golang.org/x/sys
v0.41.0
fixed in 0.44.0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-27145NONE0
stdlib
v1.26.2
fixed in 1.25.11, 1.26.4
0.6%
Theoretical Threat
Not Applicable
CVE-2026-39823NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.3%
Theoretical Threat
Not Applicable
CVE-2026-39825NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-42499NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-42504NONE0
stdlib
v1.26.2
fixed in 1.25.11, 1.26.4
0.6%
Theoretical Threat
Not Applicable