<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T15:42:02.448246+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-352794</id>
    <title>EUVD-2026-352794</title>
    <updated>2026-10-04T15:42:02.488556+00:00</updated>
    <content>EUVD-2026-352794</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-352794"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-58427</id>
    <title>fkie_cve-2026-58427</title>
    <updated>2026-10-04T15:42:02.488593+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Private org member list leaked via /members API endpoint — incomplete fix for PR #38145</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-58427"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-prr9-9mp4-5gp2</id>
    <title>GHSA-prr9-9mp4-5gp2 — Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145</title>
    <updated>2026-10-04T15:42:02.488628+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: gitea.dev</p>
<p>## Summary
PR #38145 fixed ListPublicMembers and IsPublicMember but missed 
ListMembers. Any authenticated user can enumerate ALL members 
(not just public ones) of a private organization.</p>
<p>## Affected Versions
&lt;= v1.26.4 (latest) and main branch</p>
<p>## Root Cause
routers/api/v1/org/member.go — ListMembers():</p>
<p>// Missing check:
if !organization.HasOrgOrUserVisible(ctx, 
    ctx.Org.Organization.AsUser(), ctx.Doer) {
    ctx.APIErrorNotFound()
    return
}</p>
<p>## Proof of Concept</p>
<p># Setup: privateorg (private), alice = member, bob = outsider</p>
<p># Bob lists ALL members of private org
curl -s "http://gitea/api/v1/orgs/privateorg/members" \
  -H "Authorization: token BOB_TOKEN"</p>
<p># Result: HTTP 200
[{"login":"alice","email":"alice@test.com",...}]
# Expected: HTTP 404</p>
<p>## Note
This is an incomplete fix variant of PR #38145.
That PR fixed public_members endpoints only.
ListMembers (/orgs/{org}/members) remains unpatched.</p>
<p>## Fix
Add to ListMembers():
if !organization.HasOrgOrUserVisible(ctx, 
    ctx.Org.Organization.AsUser(), ctx.Doer) {
    ctx.APIErrorNotFound()
    return
}</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-prr9-9mp4-5gp2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</id>
    <title>WID-SEC-W-2026-2304 — Gitea: Mehrere Schwachstellen</title>
    <updated>2026-10-04T15:42:02.488671+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304"/>
  </entry>
</feed>
