<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T08:25:35.073985+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-333526</id>
    <title>EUVD-2026-333526</title>
    <updated>2026-10-04T08:25:35.076496+00:00</updated>
    <content>EUVD-2026-333526</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-333526"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-22555</id>
    <title>fkie_cve-2026-22555</title>
    <updated>2026-10-04T08:25:35.076528+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCreateOrgRepo check, which can expose organization secrets.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-22555"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fhx7-m96w-mv29</id>
    <title>GHSA-fhx7-m96w-mv29 — Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration</title>
    <updated>2026-10-04T08:25:35.076557+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: code.gitea.io/gitea</p>
<p>## Summary</p>
<p>The API endpoint `POST /api/v1/repos/{owner}/{repo}/forks` only checks `IsOrgMember()` when a user forks a repository into an organization, but does not check `CanCreateOrgRepo()`. The web UI fork handler correctly checks both. This allows a read-only organization member — in a team with `can_create_org_repo=false` — to create repositories in the organization namespace via the API. The attacker receives full admin permissions on the forked repository, can enable Actions, push arbitrary workflow files, and exfiltrate all organization-level CI/CD secrets (deploy keys, cloud credentials, API tokens) through the runner infrastructure.</p>
<p>## Steps To Reproduce</p>
<p>### 1. Environment setup</p>
<p>Start a Gitea instance with Actions enabled:</p>
<p>```bash
# docker-compose.yml
cat &gt; docker-compose.yml &lt;&lt; 'EOF'
version: '3'
services:
  gitea:
    image: gitea/gitea:1.23
    container_name: gitea-poc
    ports:
      - "3000:3000"
    volumes:
      - gitea-data:/data
    environment:
      - GITEA__database__DB_TYPE=sqlite3
      - GITEA__server__ROOT_URL=http://localhost:3000/
      - GITEA__security__INSTALL_LOCK=true
      - GITEA__actions__ENABLED=true
volumes:
  gitea-data:
EOF</p>
<p>docker compose up -d
# Wait for startup
sleep 15</p>
<p># Create admin user
docker exec -u git gitea-poc gitea admin user create \
  --admin --username admin --password 'Admin1234!' \
  --email admin@example.com --must-change-password=false
```</p>
<p>### 2. Create the target environment (as admin)</p>
<p>```bash
# Get admin…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fhx7-m96w-mv29"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1172</id>
    <title>WID-SEC-W-2026-1172 — Gitea: Mehrere Schwachstellen</title>
    <updated>2026-10-04T08:25:35.076648+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um Informationen offenzulegen, um Sicherheitsvorkehrungen zu umgehen, und um einen Cross-Site Scripting Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1172"/>
  </entry>
</feed>
