<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T00:56:05.792646+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-352796</id>
    <title>EUVD-2026-352796</title>
    <updated>2026-10-04T00:56:05.795649+00:00</updated>
    <content>EUVD-2026-352796</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-352796"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-58425</id>
    <title>fkie_cve-2026-58425</title>
    <updated>2026-10-04T00:56:05.795686+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-58425"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vxv2-8j6r-pcpg</id>
    <title>GHSA-vxv2-8j6r-pcpg — Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)</title>
    <updated>2026-10-04T00:56:05.795717+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: code.gitea.io/gitea</p>
<p>## Live reproduction against Gitea 1.26.1</p>
<p>Setup: Gitea 1.26.1 docker stack with two users (`admin` and `victim`) and two OAuth applications owned by different users:</p>
<p>```
Client A: id=5dda747d-7fdd-4694-85ff-ce4f893ce51e   owner=admin
Client B: id=588f778f-4a41-4914-ae01-85d776c369db   owner=victim
```</p>
<p>`admin` runs an OAuth flow against Client A and obtains an access token. `victim` (acting through Client B's credentials) calls the introspection endpoint with Client A's access token in the body:</p>
<p>```
$ curl -s -u "$B_ID:$B_SEC" -X POST http://localhost:3001/login/oauth/introspect \
       --data-urlencode "token=$CLIENT_A_ACCESS_TOKEN"
{
    "active": true,
    "username": "admin",
    "iss": "http://localhost:3001",
    "sub": "1",
    "aud": [
        "5dda747d-7fdd-4694-85ff-ce4f893ce51e"
    ]
}
```</p>
<p>Note the `aud` claim: the server explicitly states the token's audience is Client A, yet returns the full metadata to Client B. Per RFC 7662 section 4 ("The authorization server SHOULD also limit the information it discloses about each token to the resources that are authorized to receive it") the introspection result must not be disclosed to clients other than the token's audience.</p>
<p>Full reproduction script attached as `poc.sh`. Full session log attached as `live_run.log`.</p>
<p>## Root cause</p>
<p>`routers/web/auth/oauth2_provider.go:130-175` `IntrospectOAuth`:</p>
<p>```go
func IntrospectOAuth(ctx *context.Context) {
    clientIDValid := false
    authHeader := ctx.Req.Header.Get("Auth…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vxv2-8j6r-pcpg"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</id>
    <title>WID-SEC-W-2026-2304 — Gitea: Mehrere Schwachstellen</title>
    <updated>2026-10-04T00:56:05.795787+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304"/>
  </entry>
</feed>
