
🚨Critical - Gitea: Three CI/CD & SSRF Flaws Fixed in 1.26.x (CVE-2026-58426, CVE-2026-22874, CVE-2026-58424) Gitea patched three issues, mostly in its Actions CI/CD. CVE-2026-58426 (9.6): an HMAC ambiguity in Actions Artifacts V4 signed URLs allows cross-repository artifact reads and cross-task upload-state writes. CVE-2026-22874 (9.6): incomplete SSRF protection in webhook and migration allow-list filtering lets an authenticated user reach internal services and metadata endpoints. CVE-2026-58424 (8.9): a permanent fork-PR workflow approval-gate bypass lets a fork PR author run CI workflows without the required maintainer approval, exposing runner secrets and resources. All three need only a low-privileged authenticated account, and their fixes are staggered across 1.26.2–1.26.4. 👉Upgrade Gitea to 1.26.4 (covers all three).
Post summary
The message announces the discovery of three critical Gitea vulnerabilities, provides technical details, and urges users to patch by upgrading to version 1.26.4.


