<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T00:54:42.383634+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-352285</id>
    <title>EUVD-2026-352285</title>
    <updated>2026-10-04T00:54:42.388813+00:00</updated>
    <content>EUVD-2026-352285</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-352285"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-57897</id>
    <title>fkie_cve-2026-57897</title>
    <updated>2026-10-04T00:54:42.388862+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-57897"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-frpw-3h2q-4jj6</id>
    <title>GHSA-frpw-3h2q-4jj6 — Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs</title>
    <updated>2026-10-04T00:54:42.388907+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: code.gitea.io/gitea</p>
<p>**Author:** Prakhar Porwal
**Date:** 2026-05-24
**Target:** Gitea (self-hosted Git service)
**Branch tested:** `main` @ `b7e95cc48c` (development build, go1.26.3)
**Component:** `routers/api/v1/org/action.go` (org-level Actions API)
**OWASP:** API3:2023 Broken Object Property Level Authorization</p>
<p>---</p>
<p>## 1. Summary</p>
<p>The org-level Actions REST endpoints</p>
<p>```
GET /api/v1/orgs/{org}/actions/runs
GET /api/v1/orgs/{org}/actions/jobs
```</p>
<p>are gated only by **`reqOrgMembership()`** + `reqToken()`. They then call
`shared.ListRuns(ctx, ctx.Org.Organization.ID, 0)` /
`shared.ListJobs(ctx, ctx.Org.Organization.ID, 0, 0, nil)`, which selects
**every** `action_run` / `action_run_job` row whose repository belongs to the
org — with **no per-repository ACL check**.</p>
<p>Result: any user who is a member of an organization can enumerate workflow
runs and jobs from **every repository in that org**, including:</p>
<p>* private repositories the caller has no team membership for,
* repositories where the caller has been explicitly denied the `repo.actions`
  unit,
* repositories created by other teams the caller is not part of.</p>
<p>Direct per-repo equivalents (`GET /api/v1/repos/{owner}/{repo}/actions/runs`,
`…/jobs/{job_id}/logs`, `…/runs/{run_id}/jobs`) correctly return `404` for the
same caller — proving the org-level surface is the only path that leaks.</p>
<p>---</p>
<p>## 2. Affected Code</p>
<p>### 2.1 Route registration</p>
<p>`routers/api/v1/api.go:1647-1652`</p>
<p>```go
addActionsRoutes(
    m,
    reqOrgMembership(),   // reqR…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-frpw-3h2q-4jj6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</id>
    <title>WID-SEC-W-2026-2304 — Gitea: Mehrere Schwachstellen</title>
    <updated>2026-10-04T00:54:42.389079+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304"/>
  </entry>
</feed>
