CVE-2026-58426Disclosure

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-347

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-07-03); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-07-03: 2Mentions · 2026-07-04: 1Patch / Workaround · 2026-07-04: 1Technical Details · 2026-07-03: 2Technical Details · 2026-07-04: 107-0307-04
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-07-032
Disclosure2
2026-07-041
Patch1
Full discourse3 posts
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - Gitea: Three CI/CD & SSRF Flaws Fixed in 1.26.x (CVE-2026-58426, CVE-2026-22874, CVE-2026-58424) Gitea patched three issues, mostly in its Actions CI/CD. CVE-2026-58426 (9.6): an HMAC ambiguity in Actions Artifacts V4 signed URLs allows cross-repository artifact reads and cross-task upload-state writes. CVE-2026-22874 (9.6): incomplete SSRF protection in webhook and migration allow-list filtering lets an authenticated user reach internal services and metadata endpoints. CVE-2026-58424 (8.9): a permanent fork-PR workflow approval-gate bypass lets a fork PR author run CI workflows without the required maintainer approval, exposing runner secrets and resources. All three need only a low-privileged authenticated account, and their fixes are staggered across 1.26.2–1.26.4. 👉Upgrade Gitea to 1.26.4 (covers all three).

    Post summary

    The message announces the discovery of three critical Gitea vulnerabilities, provides technical details, and urges users to patch by upgrading to version 1.26.4.

    00000117
    236 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-58426 Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write https://www.cve.org/CVERecord?id=CVE-2026-58426 ----- Traducción: CVE-2026-58426 Gitea Actions Artefacts URL firmado HMAC ambigü… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-58426, providing its ID, a brief technical description, and links to official and community resources, with no evidence of PoC, exploit, or active exploitation.

    0000038
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-58426 Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write https://www.cve.org/CVERecord?id=CVE-2026-58426

    Post summary

    The post announces CVE-2026-58426, describing that an HMAC ambiguity in Gitea Actions Artifacts V4 allows cross‑repository reads and cross‑task write operations, but it does not mention any PoC, exploit tool, patch, or active exploitation.

    00000684
    57.7K followersView on X

Explore more