Review reviewCritical
CVE-2026-58426
Gitea Gitea Open Source Git Server
Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write
- CVSS
- 9.6
- EPSS
- 0.18% 7.49% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.04