<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T04:48:37.317906+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-352801</id>
    <title>EUVD-2026-352801</title>
    <updated>2026-10-04T04:48:37.320733+00:00</updated>
    <content>EUVD-2026-352801</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-352801"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-57886</id>
    <title>fkie_cve-2026-57886</title>
    <updated>2026-10-04T04:48:37.320765+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Cross-repository issue/comment attachment re-linking can expose private attachment content</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-57886"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6c6r-5xr4-cr5m</id>
    <title>GHSA-6c6r-5xr4-cr5m — Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content</title>
    <updated>2026-10-04T04:48:37.320796+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: code.gitea.io/gitea</p>
<p>## Summary</p>
<p>Gitea's issue and comment attachment update paths accept attachment UUIDs without verifying that each attachment belongs to the target issue/comment repository. If an authenticated attacker knows a victim attachment UUID, they can re-link that attachment to an attacker-controlled issue or comment, causing later attachment access checks to use the attacker's repository authorization context.</p>
<p>## Affected</p>
<p>- Component: web issue/comment attachment handling.
- Confirmed version: `main` commit `a39b2775edcb3ba53def96794491b91335117d81` (`v1.27.0-dev-352-ga39b2775ed`).
- Fixed in: not fixed at the time of validation.
- Other versions: not exhaustively tested. The affected code path appears structurally similar to versions that contain the current issue/comment attachment update logic.</p>
<p>## Description / Root Cause</p>
<p>`files[]` values from issue/comment edit flows are passed to `updateAttachments` in `routers/web/repo/issue.go:589-629`. That helper calls:</p>
<p>- `models/issues/issue_update.go:267-278` (`UpdateIssueAttachments`)
- `models/issues/comment.go:623-642` (`UpdateCommentAttachments`)</p>
<p>Both functions load attachments by UUID and update the attachment linkage, but neither validates that the attachment row's `RepoID` matches the repository of the target issue/comment. They also do not reject attachments already linked to a different issue/comment.</p>
<p>Attachment reads then use the linked issue/release repository to decide access:</p>
<p>- `services/repository/repository.go:185-2…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6c6r-5xr4-cr5m"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</id>
    <title>WID-SEC-W-2026-2304 — Gitea: Mehrere Schwachstellen</title>
    <updated>2026-10-04T04:48:37.320856+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304"/>
  </entry>
</feed>
