<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T13:00:28.482670+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-352921</id>
    <title>EUVD-2026-352921</title>
    <updated>2026-10-04T13:00:28.530032+00:00</updated>
    <content>EUVD-2026-352921</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-352921"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-56443</id>
    <title>fkie_cve-2026-56443</title>
    <updated>2026-10-04T13:00:28.530070+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-56443"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7p4h-3gxq-x3h3</id>
    <title>GHSA-7p4h-3gxq-x3h3 — Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after…</title>
    <updated>2026-10-04T13:00:28.530104+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: code.gitea.io/gitea, Go: gitea.dev</p>
<p>## Summary</p>
<p>After [PR #37118](https://github.com/go-gitea/gitea/pull/37118) / **CVE-2026-25714**
(`fix: Unify public-only token filtering in API queries and repo access checks`,
merged 2026-05-18, backport `#37773` to 1.26.2 — the May 2026 unification pass
for public-only token filtering, reporter Medoedus per the 1.26.2 release notes),
the `public-only` PAT scope is still bypassable on **Repository** and **Package**
scope categories when the owner's `Visibility = Limited` (instance-internal).</p>
<p>The sibling `Org` / `User` / `ActivityPub` cases in the same `checkTokenPublicOnly`
switch correctly reject Limited owners via `!Visibility.IsPublic()`. The
Repository / Package cases use `repo.IsPrivate` or `Owner.Visibility.IsPrivate()`,
both of which return `false` for `VisibleTypeLimited` — so a `public-only` PAT
strictly exceeds anonymous reach on a Limited owner.</p>
<p>Tested on `gitea/gitea:1.26.2`. The decisive marker is that PR #37118's
unification IS applied in the version under test (User-category PROBE returns
`403 "token scope is limited to public users"`). Despite that, the
Repository-category PROBE on the same Limited owner with the same PAT returns
`200` and serves content.</p>
<p>## Affected entry points (4 spots)</p>
<p>| File:Line | Function | Affected surface |
|---|---|---|
| `routers/api/v1/api.go:292` | `checkTokenPublicOnly` Package case | API v1 packages |
| `routers/api/packages/api.go:76` | `reqPackageAccess` middleware | All 24 native package registries (`/api/packages/&lt;typ…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7p4h-3gxq-x3h3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</id>
    <title>WID-SEC-W-2026-2304 — Gitea: Mehrere Schwachstellen</title>
    <updated>2026-10-04T13:00:28.530181+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304"/>
  </entry>
</feed>
