<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T06:06:05.410974+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-330206</id>
    <title>EUVD-2026-330206</title>
    <updated>2026-10-03T06:06:05.413938+00:00</updated>
    <content>EUVD-2026-330206</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-330206"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-52801</id>
    <title>fkie_cve-2026-52801</title>
    <updated>2026-10-03T06:06:05.413975+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Gogs Mirror Settings functionality provide an alternative way from the well protected New Migration functionality for any authenticated users to import local repositories. This issue stems from a lack of validation of SaveAddress function. This vulnerability is fixed in 0.14.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-52801"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-wv27-2vqp-j7g5</id>
    <title>GHSA-wv27-2vqp-j7g5 — Gogs has the ability to import local repositories via Mirror Settings</title>
    <updated>2026-10-03T06:06:05.414006+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: gogs.io/gogs</p>
<p>### Summary
The Gogs Mirror Settings functionality provide an alternative way from the well protected New Migration functionality for any authenticated users to import local repositories. This issue stems from a lack of validation of SaveAddress function.</p>
<p>### Details
Here is the function implementation of the secure New Migration functionality.
&lt;img width="1200" height="755" alt="image" src="https://github.com/user-attachments/assets/a6c2f307-715e-4451-bbc1-7bd934d56f96" /&gt;</p>
<p>Here is the function implementation of the Mirror Settings without any validation.
&lt;img width="1200" height="477" alt="image" src="https://github.com/user-attachments/assets/a11c41b8-1d08-499c-bce6-ab40844211d7" /&gt;</p>
<p>### PoC
The New Migration feature correctly blocked my attempt to import a local repository.
&lt;img width="1200" height="1008" alt="image" src="https://github.com/user-attachments/assets/dfc5aa3f-1cc4-427d-b7fe-274363c83c4e" /&gt;</p>
<p>But if I create a normal migration with a valid repository.
&lt;img width="1200" height="1006" alt="image" src="https://github.com/user-attachments/assets/c96b356e-8ca9-4e79-a69b-ff14593c0cac" /&gt;</p>
<p>Then, I could use the Mirror Settings feature under the Repository Settings sync a local repository.
&lt;img width="1200" height="476" alt="image" src="https://github.com/user-attachments/assets/9105475c-ae68-4d93-96d5-a3ec356deba7" /&gt;</p>
<p>Here is the result after the sync.
&lt;img width="1200" height="533" alt="image" src="https://github.com/user-attachments/assets/1df76642-3e55-4493-a4…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-wv27-2vqp-j7g5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2013</id>
    <title>WID-SEC-W-2026-2013 — Gogs: Mehrere Schwachstellen</title>
    <updated>2026-10-03T06:06:05.414053+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Gogs ausnutzen, um erweiterte Berechtigungen zu erlangen, beliebigen Code auszuführen – sogar mit erweiterten Berechtigungen, was zur vollständigen Kontrolle über das System führen kann –, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, Cross-Site-Scripting-Angriffe durchzuführen, Benutzer auf bösartige Websites umzuleiten oder einen Denial-of-Service-Zustand zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2013"/>
  </entry>
</feed>
