<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T23:43:01.586043+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-10563</id>
    <title>bdu:2026-10563</title>
    <updated>2026-10-03T23:43:01.589248+00:00</updated>
    <content>bdu:2026-10563</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-10563"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-333353</id>
    <title>EUVD-2026-333353</title>
    <updated>2026-10-03T23:43:01.589282+00:00</updated>
    <content>EUVD-2026-333353</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-333353"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-27783</id>
    <title>fkie_cve-2026-27783</title>
    <updated>2026-10-03T23:43:01.589297+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Gitea versions up to and including 1.26.1 do not enforce repository-unit authorization on issue-template API endpoints.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-27783"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3fwp-p5rj-2pxf</id>
    <title>GHSA-3fwp-p5rj-2pxf — Gitea: Missing repository-unit authorization on issue-template API endpoints</title>
    <updated>2026-10-03T23:43:01.589325+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: code.gitea.io/gitea</p>
<p>## Summary</p>
<p>Three Gitea API endpoints — `GET /repos/{owner}/{repo}/issue_templates`,
`GET /repos/{owner}/{repo}/issue_config` and `GET /repos/{owner}/{repo}/issue_config/validate`
— read files from the repository's **Code** default branch (`.gitea/ISSUE_TEMPLATE/*`
and `issue_config.yaml`) and return their contents, but are registered **without**
the `reqRepoReader(unit.TypeCode)` authorization middleware that every sibling
Code-tree endpoint in the same route group carries.</p>
<p>A user who has access to a private repository through *any single repository unit*
(for example an organization team granted only the **Issues** unit, with no Code
access) can therefore read the issue-template and issue-config files of that
repository's Code tree, which their permission set should not expose.</p>
<p>---</p>
<p>## Root cause</p>
<p>### The three endpoints lack the unit guard</p>
<p>`routers/api/v1/api.go:1433-1437`:</p>
<p>m.Get("/issue_templates", context.ReferencesGitRepo(), repo.GetIssueTemplates)
    m.Get("/issue_config", context.ReferencesGitRepo(), repo.GetIssueConfig)
    m.Get("/issue_config/validate", context.ReferencesGitRepo(), repo.ValidateIssueConfig)
    m.Get("/languages", reqRepoReader(unit.TypeCode), repo.GetLanguages)
    m.Get("/licenses", reqRepoReader(unit.TypeCode), repo.GetLicenses)</p>
<p>`context.ReferencesGitRepo()` only opens the git repository — it performs no
permission check. Every other endpoint in this group that reads Code-tree content
is guarded with `reqRepoReader(unit.TypeCode)`: `/…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3fwp-p5rj-2pxf"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1637</id>
    <title>WID-SEC-W-2026-1637 — Gitea: Mehrere Schwachstellen</title>
    <updated>2026-10-03T23:43:01.589388+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um möglicherweise erweiterte Privilegien zu erlangen, Sicherheitsmaßnahmen zu umgehen oder Daten zu manipulieren und offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1637"/>
  </entry>
</feed>
