<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T01:44:40.247714+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-09234</id>
    <title>bdu:2026-09234</title>
    <updated>2026-10-04T01:44:40.326519+00:00</updated>
    <content>bdu:2026-09234</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-09234"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-333756</id>
    <title>EUVD-2026-333756</title>
    <updated>2026-10-04T01:44:40.326565+00:00</updated>
    <content>EUVD-2026-333756</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-333756"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-22874</id>
    <title>fkie_cve-2026-22874</title>
    <updated>2026-10-04T01:44:40.326590+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-22874"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2r5c-gw76-rh3w</id>
    <title>GHSA-2r5c-gw76-rh3w — Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter</title>
    <updated>2026-10-04T01:44:40.326631+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: code.gitea.io/gitea</p>
<p>## Summary</p>
<p>Gitea's default SSRF allow-list ([`MatchBuiltinExternal`](https://github.com/go-gitea/gitea/blob/4c37f4dacbac022f7beca75272439331f0368830/modules/hostmatcher/hostmatcher.go#L26-L27), used by both webhook delivery and repository migrations) relies on Go's standard library [`net.IP.IsPrivate()`](https://pkg.go.dev/net#IP.IsPrivate), which only covers RFC 1918 and RFC 4193. As a result, several IP ranges commonly used for cloud metadata services, internal networks, and IPv6 transition mechanisms are not blocked, allowing authenticated users to send HTTP requests to those destinations and read the responses via the webhook history UI.</p>
<p>## Details</p>
<p>The vulnerability lives in [`HostMatchList.checkIP`](https://github.com/go-gitea/gitea/blob/4c37f4dacbac022f7beca75272439331f0368830/modules/hostmatcher/hostmatcher.go#L96-L114), specifically [line 103](https://github.com/go-gitea/gitea/blob/4c37f4dacbac022f7beca75272439331f0368830/modules/hostmatcher/hostmatcher.go#L103):</p>
<p>```go
case MatchBuiltinExternal:
    if ip.IsGlobalUnicast() &amp;&amp; !ip.IsPrivate() {
        return true
    }
```</p>
<p>`net.IP.IsPrivate()` recognises only:
- `10.0.0.0/8`, `172.16.0.0/12`, `192.168.0.0/16` (RFC 1918)
- `fc00::/7` (RFC 4193 IPv6 ULA)</p>
<p>It does **not** recognise:</p>
<p>| Range | Description |
|---|---|
| `100.64.0.0/10` | RFC 6598 Carrier-Grade NAT |
| `168.63.129.16/32` | Azure WireServer metadata endpoint |
| `172.32.0.0/11` | Non-RFC1918 portion of `172.0.0.0/8` (real-world internal use) |
| `64:f…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2r5c-gw76-rh3w"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2027</id>
    <title>WID-SEC-W-2026-2027 — Gitea: Mehrere Schwachstellen</title>
    <updated>2026-10-04T01:44:40.326766+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um erweiterte Berechtigungen zu erlangen, sich als Benutzer auszugeben, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren und vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2027"/>
  </entry>
</feed>
