Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-32947

Опубликовано: 20 мар. 2026
Источник: redhat
CVSS3: 4.9
EPSS Низкий

Описание

Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. In versions 2.15.1 and below, a DNS over HTTPS (DoH) vulnerability allows attackers to bypass egress-policy: block network restrictions by tunneling exfiltrated data through permitted HTTPS endpoints like dns.google. The attack works by encoding sensitive data (e.g., the runner's hostname) as subdomains in DoH queries, which appear as legitimate HTTPS traffic to Harden-Runner's domain-based filtering but are ultimately forwarded to an attacker-controlled domain. This effectively enables data exfiltration without directly connecting to any blocked destination. Exploitation requires the attacker to already have code execution within the GitHub Actions workflow. The issue was fixed in version 2.16.0.

A flaw was found in Harden-Runner. A remote attacker with existing code execution within a GitHub Actions workflow could exploit a DNS over HTTPS (DoH) vulnerability to bypass network restrictions. This allows for the exfiltration of sensitive data by encoding it within DoH queries, which appear as legitimate HTTPS traffic, effectively bypassing egress policies.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/bitwarden-sdk-server-rhel9Fix deferred
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/external-secrets-operator-bundleFix deferred
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/external-secrets-operator-rhel9Fix deferred
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/external-secrets-rhel9Fix deferred
Gatekeeper 3gatekeeper/gatekeeper-rhel9Fix deferred
Multicluster Engine for Kubernetesmulticluster-engine/addon-manager-rhel9Out of support scope
Multicluster Engine for Kubernetesmulticluster-engine/placement-rhel9Out of support scope
Multicluster Engine for Kubernetesmulticluster-engine/registration-operator-rhel9Out of support scope
Multicluster Engine for Kubernetesmulticluster-engine/registration-rhel9Out of support scope
Multicluster Engine for Kubernetesmulticluster-engine/work-rhel9Out of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-807
https://bugzilla.redhat.com/show_bug.cgi?id=2449437harden-runner: Harden-Runner: Data exfiltration via DNS over HTTPS (DoH) bypass

EPSS

Процентиль: 23%
0.00305
Низкий

4.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.9
nvd
5 месяцев назад

Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. In versions 2.15.1 and below, a DNS over HTTPS (DoH) vulnerability allows attackers to bypass egress-policy: block network restrictions by tunneling exfiltrated data through permitted HTTPS endpoints like dns.google. The attack works by encoding sensitive data (e.g., the runner's hostname) as subdomains in DoH queries, which appear as legitimate HTTPS traffic to Harden-Runner's domain-based filtering but are ultimately forwarded to an attacker-controlled domain. This effectively enables data exfiltration without directly connecting to any blocked destination. Exploitation requires the attacker to already have code execution within the GitHub Actions workflow. The issue was fixed in version 2.16.0.

github
5 месяцев назад

Egress Policy Bypass via DNS over HTTPS (DoH) in Harden-Runner (Community Tier)

EPSS

Процентиль: 23%
0.00305
Низкий

4.9 Medium

CVSS3