<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T01:45:02.773541+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-352802</id>
    <title>EUVD-2026-352802</title>
    <updated>2026-10-04T01:45:02.822942+00:00</updated>
    <content>EUVD-2026-352802</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-352802"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55984</id>
    <title>fkie_cve-2026-55984</title>
    <updated>2026-10-04T01:45:02.822975+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-55984"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-m932-crvm-gcp5</id>
    <title>GHSA-m932-crvm-gcp5 — Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service</title>
    <updated>2026-10-04T01:45:02.823004+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: code.gitea.io/gitea</p>
<p>### Summary</p>
<p>The AddTime API handler continues execution after an error returned by `GetUserByName()`.</p>
<p>When a repository administrator specifies a non-existent user name, an error response is generated but execution does not stop. Subsequent code dereferences a nil user pointer, resulting in a runtime panic.</p>
<p>### Details</p>
<p>Affected endpoint:</p>
<p>```http
POST /api/v1/repos/{owner}/{repo}/issues/{index}/times
```</p>
<p>Affected file:</p>
<p>```text
routers/api/v1/repo/issue_tracked_time.go
```</p>
<p>Relevant code:</p>
<p>```go
user, err = user_model.GetUserByName(ctx, form.User)
if err != nil {
    ctx.APIErrorInternal(err)
    // missing return
}
```</p>
<p>Execution continues to:</p>
<p>```go
trackedTime, err := issues_model.AddTime(
    ctx,
    user,
    issue,
    form.Time,
    created,
)
```</p>
<p>When `GetUserByName()` fails, `user` is nil.</p>
<p>The subsequent call dereferences the nil pointer and triggers a runtime panic.</p>
<p>### Proof of Concept</p>
<p>Using a repository administrator account:</p>
<p>```http
POST /api/v1/repos/owner/repo/issues/1/times
Content-Type: application/json</p>
<p>{
  "time": 3600,
  "user_name": "nonexistent_user_xyz"
}
```</p>
<p>Result:</p>
<p>```text
HTTP 500
runtime error: invalid memory address or nil pointer dereference
```</p>
<p>The stack trace indicates execution reaches the AddTime code path with a nil user object.</p>
<p>### Impact</p>
<p>An authenticated repository administrator can repeatedly trigger server-side panics through the affected endpoint.</p>
<p>Depending on deployment configuration and panic recovery behavior, this m…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-m932-crvm-gcp5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</id>
    <title>WID-SEC-W-2026-2304 — Gitea: Mehrere Schwachstellen</title>
    <updated>2026-10-04T01:45:02.823059+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304"/>
  </entry>
</feed>
