Observable discrepancy in Gitea - CVE-2026-73504
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote attacker to confirm the association between an artifact ID and a named private repository.
The vulnerability exists due to observable discrepancy in the raw Actions artifact download endpoint when validating signed artifact download URLs. A remote attacker can submit requests with guessed global artifact IDs and an invalid signature to confirm the association between an artifact ID and a named private repository.
Artifact contents are not exposed, and inaccessible and nonexistent repositories return the same status.