<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T11:35:06.605049+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-12013</id>
    <title>bdu:2026-12013</title>
    <updated>2026-10-04T11:35:06.608042+00:00</updated>
    <content>bdu:2026-12013</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-12013"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-333741</id>
    <title>EUVD-2026-333741</title>
    <updated>2026-10-04T11:35:06.608075+00:00</updated>
    <content>EUVD-2026-333741</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-333741"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-27761</id>
    <title>fkie_cve-2026-27761</title>
    <updated>2026-10-04T11:35:06.608090+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Gitea versions up to and including 1.26.2 allow repository RSS and Atom feed endpoints to bypass API access token scope checks, exposing private repository commit data to tokens without the required repository scope.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-27761"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3pww-vcvm-3gmj</id>
    <title>GHSA-3pww-vcvm-3gmj — Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit…</title>
    <updated>2026-10-04T11:35:06.608119+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: code.gitea.io/gitea</p>
<p>### Summary
A Gitea personal access token (PAT) restricted to a non-repository scope (e.g. `read:issue`) can read the commit history of any private repository the token owner can access, via the repository RSS/Atom feed endpoints. The same token is correctly denied (403) on `/raw`, `/media`, `/archive`, and the contents API. It leaks commit SHAs, full commit messages (which frequently contain secrets and internal context), and committer name + email.</p>
<p>### Details
Gitea enforces PAT scope on repository-content endpoints via `checkDownloadTokenScope()` (added in PR #37698, extended to the archive endpoint by the CVE-2026-20706 fix in 1.26.2). The RSS/Atom feed handlers were never included: they (a) opt into PAT auth via `webAuth.AllowBasic`, (b) serve private-repo content, but (c) never call `checkDownloadTokenScope()`.</p>
<p>Affected handlers (all carry `AllowBasic`, none call the scope check):
- `RenderBranchFeedRSS/Atom` - `routers/web/feed/render.go` (last 10 commits: SHA, title, full message, committer name + email)
- `ShowFileFeed` - `routers/web/feed/file.go` (per-file commit history)
- repo activity feed `/{owner}/{repo}.rss` / `.atom`
- `TagsListFeedRSS/Atom`, `ReleasesFeedRSS/Atom` - `routers/web/repo/release.go`</p>
<p>Root cause: `routers/web/web.go` registers the feed routes with `webAuth.AllowBasic` so a PAT authenticates, but the unit-permission middleware only checks the user's access, not the token's scope. `checkDownloadTokenScope` (`routers/web/repo/download.go` and th…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3pww-vcvm-3gmj"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2027</id>
    <title>WID-SEC-W-2026-2027 — Gitea: Mehrere Schwachstellen</title>
    <updated>2026-10-04T11:35:06.608168+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um erweiterte Berechtigungen zu erlangen, sich als Benutzer auszugeben, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren und vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2027"/>
  </entry>
</feed>
