Published 7/3/2026 · updated 7/3/2026 · CWE-347
Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Percentile p7 — Lower risk — in the top 93% least-likely-to-be-exploited CVEs.
Which upstream feeds returned data for this CVE, and when they were last fetched.
Unlock the full report
Free public data ends here. Sign in to correlate this CVE against your SBOM and assets, get an AI-grounded exploit chain, generate a ModSecurity virtual patch, and share findings with your team.