—
GO-2026-6060
Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Quick fix
GO-2026-6060 — code.gitea.io/gitea: upgrade to the fixed version with the command below.
go get code.gitea.io/gitea@v1.26.2 Details
Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Are you affected?
Enter the version of the package you're using.
Affected packages
Go / code.gitea.io/gitea
Introduced in:
1.22.0 Fixed in: 1.26.2 Fix
go get code.gitea.io/gitea@v1.26.2 References
- https://github.com/go-gitea/gitea/security/advisories/GHSA-hg5r-vq93-9fv6 [ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-58426 [ADVISORY]
- https://blog.gitea.com/release-of-1.26.2 [WEB]
- https://github.com/go-gitea/gitea/commit/1c2d5e9b03f71dd12d450b2af9a79f2557b50226 [WEB]
- https://github.com/go-gitea/gitea/pull/37707 [WEB]
- https://github.com/go-gitea/gitea/releases/tag/v1.26.2 [WEB]