<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T08:07:07.537574+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-352788</id>
    <title>EUVD-2026-352788</title>
    <updated>2026-10-04T08:07:07.586416+00:00</updated>
    <content>EUVD-2026-352788</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-352788"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-58436</id>
    <title>fkie_cve-2026-58436</title>
    <updated>2026-10-04T08:07:07.586461+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-58436"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fw57-jgch-pgf3</id>
    <title>GHSA-fw57-jgch-pgf3 — Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests</title>
    <updated>2026-10-04T08:07:07.586492+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: code.gitea.io/gitea</p>
<p>### Summary</p>
<p>The Locale middleware that runs in front of every unauthenticated request
calls `golang.org/x/text/language.ParseAcceptLanguage` on the raw
`Accept-Language` header without imposing a size or shape filter. The
underlying parser has quadratic-time behaviour on long lists of malformed
language tags. The CVE-2022-32149 guard that golang.org/x/text added in
v0.3.8 caps the number of `-` characters in the input at 1000, but it does
not cap `_` characters even though the parser's internal scanner aliases
`_` to `-` before parsing. A single unauthenticated GET request with an
`Accept-Language` header built out of `_` separators burns ~2 seconds of
server CPU on the host running Gitea; ten concurrent attackers saturate a
ten-core box for the duration of the attack while consuming ~1 MiB of
upstream bandwidth per request.</p>
<p>### Affected versions</p>
<p>`code.gitea.io/gitea` 1.22.6 and (per code inspection of `main`) all
earlier and later 1.22.x / 1.23.x / 1.24.x / 1.25.x / 1.26.x versions that
do not impose their own size limit on the `Accept-Language` header before
calling `ParseAcceptLanguage`. Verified on:</p>
<p>- the official `gitea/gitea:1.22.6` docker image (E2E below)
- `main` at commit `6f4027a6be28c876c0abaf37cc939658645b78a3` by reading
  `modules/web/middleware/locale.go` (the call site at line 38 is unchanged
  on `main`)</p>
<p>### Privilege required</p>
<p>Unauthenticated. The Locale middleware runs for every HTTP request
including the landing page and the sign-in page.</p>
<p>### Vulne…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fw57-jgch-pgf3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</id>
    <title>WID-SEC-W-2026-2304 — Gitea: Mehrere Schwachstellen</title>
    <updated>2026-10-04T08:07:07.586565+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304"/>
  </entry>
</feed>
