<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T23:41:13.096516+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-333747</id>
    <title>EUVD-2026-333747</title>
    <updated>2026-10-03T23:41:13.105848+00:00</updated>
    <content>EUVD-2026-333747</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-333747"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-26231</id>
    <title>fkie_cve-2026-26231</title>
    <updated>2026-10-03T23:41:13.105889+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to repositories that the user can read but should not be able to write.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-26231"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mm7c-rhg6-qr4r</id>
    <title>GHSA-mm7c-rhg6-qr4r — Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo</title>
    <updated>2026-10-03T23:41:13.105923+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: code.gitea.io/gitea</p>
<p>## Summary</p>
<p>Any authenticated low-privilege user with read access to a repository can push arbitrary commits directly to that repository, bypassing all write-access checks.</p>
<p>## Vulnerability</p>
<p>Gitea's "Allow edits from maintainers" PR option can be abused via reverse-fork PRs:</p>
<p>1. The web UI PR-create endpoint binds `allow_maintainer_edit=true` **without** verifying that the submitter has write access to the HEAD repository.
2. Gitea allows creating a PR where **BASE = attacker's fork** and **HEAD = upstream target**. The attacker is "maintainer" of the BASE (their own fork), so the flag is set against the upstream HEAD.
3. On `git push` over HTTP/SSH, Gitea relaxes the required access mode to `Read` when `SupportProcReceive` is enabled ([`routers/web/repo/githttp.go`](https://github.com/go-gitea/gitea/blob/v1.25.5/routers/web/repo/githttp.go#L189), [`routers/private/serv.go`](https://github.com/go-gitea/gitea/blob/v1.25.5/routers/private/serv.go#L337)) and defers enforcement to the pre-receive hook.
4. The pre-receive hook calls [`CanMaintainerWriteToBranch`](https://github.com/go-gitea/gitea/blob/v1.25.5/models/issues/pull_list.go#L72) (`models/issues/pull_list.go`), which finds the malicious PR, sees `AllowMaintainerEdit=true`, and checks whether the pusher has write access to the **BASE** repo. Since BASE is the attacker's own fork, the check passes and the push is authorized against the upstream.</p>
<p>## Exploitation</p>
<p>1. Attacker forks the target repository.
2. Attacker visi…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mm7c-rhg6-qr4r"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1637</id>
    <title>WID-SEC-W-2026-1637 — Gitea: Mehrere Schwachstellen</title>
    <updated>2026-10-03T23:41:13.105981+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um möglicherweise erweiterte Privilegien zu erlangen, Sicherheitsmaßnahmen zu umgehen oder Daten zu manipulieren und offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1637"/>
  </entry>
</feed>
