<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T15:57:12.358809+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-333340</id>
    <title>EUVD-2026-333340</title>
    <updated>2026-10-04T15:57:12.425149+00:00</updated>
    <content>EUVD-2026-333340</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-333340"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-58423</id>
    <title>fkie_cve-2026-58423</title>
    <updated>2026-10-04T15:57:12.425186+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-58423"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7wvc-rvp7-w99x</id>
    <title>GHSA-7wvc-rvp7-w99x — Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories</title>
    <updated>2026-10-04T15:57:12.425219+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: code.gitea.io/gitea</p>
<p>### Summary</p>
<p>A flaw in SSH LFS sub-verb handling allows any authenticated SSH user to obtain valid LFS credentials for any repository on the instance, including private repositories they have no access to. This enables unauthorized download of all LFS objects from any private repository.</p>
<p>### Details</p>
<p>In `cmd/serv.go`, the `getAccessMode` function determines the required access level for SSH operations. For LFS verbs (`git-lfs-authenticate`, `git-lfs-transfer`), it switches on the sub-verb (`upload`/`download`). If the sub-verb is neither, execution falls through to:</p>
<p>```go
setting.PanicInDevOrTesting("unknown verb: %s %s", verb, lfsVerb)
return perm.AccessModeNone
```</p>
<p>In production (`IsProd=true`), `PanicInDevOrTesting` only logs an error and does not panic. `AccessModeNone` (value `0`) is then passed to `ServCommand` in `routers/private/serv.go`, where the permission check block at line ~322 evaluates:</p>
<p>```go
if repoExist &amp;&amp;
    (mode &gt; perm.AccessModeRead ||
     repo.IsPrivate ||
     owner.Visibility.IsPrivate() ||
     (user != nil &amp;&amp; user.IsRestricted) ||
     setting.Service.RequireSignInViewStrict) {
    ...
    if userMode &lt; mode {  // userMode &lt; 0 is always false
        // deny access
    }
}
```</p>
<p>For private repositories, `repo.IsPrivate` triggers the permission check block, but `userMode &lt; mode` evaluates to `userMode &lt; 0`, which is always false — **access is granted regardless of the user's actual permissions**.</p>
<p>The function then returns successfully, and `r…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7wvc-rvp7-w99x"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2149</id>
    <title>WID-SEC-W-2026-2149 — Gitea: Mehrere Schwachstellen</title>
    <updated>2026-10-04T15:57:12.425281+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um seine Privilegien zu erhöhen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2149"/>
  </entry>
</feed>
