Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
NVD published the first details for CVE-2026-58426
A CVSS base score of 9.6 has been assigned.
Feedly found the first article mentioning CVE-2026-58426 . See article
A critical vulnerability rated 9.6 CVSS exists in Gitea Actions Artifacts V4, allowing attackers to exploit HMAC ambiguities in signed URLs to read artifacts from unauthorized repositories and modify task states. Currently, there are no public proof-of-concept exploits, patches, or mitigation details available, and the vulnerability's exploitation specifics, including whether it is actively being exploited in the wild, remain unspecified. Analysts should monitor official Gitea channels for updates and remediation guidance. See article
Gitea Actions Artifacts HMAC Ambiguity Allows Cross-Repository Access
CVE-2026-58426 - Exploits & Severity - Feedly
Gitea Actions Artifacts HMAC Ambiguity Allows Cross-Repository Access
CVE-2026-58426 | Gitea up to 1.26.1 signature verification (GHSA-hg5r-vq93-9fv6)
CVE-2026-58426 - Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write
Collect, analyze, and vulnerability reports faster using AI
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
