<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T16:21:55.759458+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-333339</id>
    <title>EUVD-2026-333339</title>
    <updated>2026-10-03T16:21:55.816961+00:00</updated>
    <content>EUVD-2026-333339</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-333339"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-58424</id>
    <title>fkie_cve-2026-58424</title>
    <updated>2026-10-03T16:21:55.816998+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Permanent Fork PR Workflow Approval Gate Bypass</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-58424"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-777r-4v59-6486</id>
    <title>GHSA-777r-4v59-6486 — Gitea: Permanent Fork PR Workflow Approval Gate Bypass</title>
    <updated>2026-10-03T16:21:55.817029+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: code.gitea.io/gitea</p>
<p>| Field | Value |
|-------|-------|
| **Identifier (researcher-assigned)** | GITEA-2026-004 |
| **Product** | Gitea (self-hosted Git service) |
| **Component** | Gitea Actions — fork pull request approval gate |
| **Affected versions** | All Gitea releases **`v1.20.0` and later**, including the latest `main` (`1.27.0+dev-289-gb7e95cc48c`). The buggy logic was introduced in commit `edf98a2dc3` — *"Require approval to run actions for fork pull request (#22803)"*, 2023-02-24 — and has shipped unchanged since. |
| **Fixed in** | not yet (this disclosure) |
| **Authentication required** | Yes — one unprivileged Gitea account capable of forking the target repository (the default ability for every authenticated user) |
| **User interaction required** | Exactly **once** — a repository administrator must approve a single benign fork PR's workflow run from the attacker. After that, *no further interaction is ever required* for any future fork PR from the same attacker on the same repository. |
| **Discovered by** | Prakhar Porwal — `prakharporwal2004@gmail.com` |
| **Live-verified on** | Gitea `main` at commit `b7e95cc48cc0e0d6fe24c89bb83da5b84a74490f`, 2026-05-24 |</p>
<p>---</p>
<p>## 1. Executive summary</p>
<p>Gitea Actions enforces an approval gate on workflow runs triggered by fork pull requests, so that an untrusted contributor cannot execute arbitrary workflow YAML on the maintainer's runner infrastructure without explicit consent. The gate is implemented by `ifNeedApproval()` in `services/acti…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-777r-4v59-6486"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2149</id>
    <title>WID-SEC-W-2026-2149 — Gitea: Mehrere Schwachstellen</title>
    <updated>2026-10-03T16:21:55.817168+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um seine Privilegien zu erhöhen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2149"/>
  </entry>
</feed>
