<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T20:39:19.906643+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-352915</id>
    <title>EUVD-2026-352915</title>
    <updated>2026-10-03T20:39:19.909549+00:00</updated>
    <content>EUVD-2026-352915</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-352915"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-58442</id>
    <title>fkie_cve-2026-58442</title>
    <updated>2026-10-03T20:39:19.909580+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Repository migration SSRF via multi-answer DNS allow-list bypass</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-58442"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-h2x6-g7q6-344v</id>
    <title>GHSA-h2x6-g7q6-344v — Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass</title>
    <updated>2026-10-03T20:39:19.909609+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: code.gitea.io/gitea</p>
<p>### Summary</p>
<p>Gitea's repository migration URL validation can be bypassed when a migration hostname resolves to multiple IP addresses. The validation logic accepts the destination if **any** resolved IP is allowed, even if another resolved IP is loopback, private, or otherwise blocked. The later `git clone` operation resolves the hostname again outside of that validation decision, so it can connect to the internal address.</p>
<p>An authenticated low-privilege user who can create repository migrations can use an attacker-controlled DNS name to make Gitea connect to internal-only Git services and import their contents into a repository controlled by the attacker.</p>
<p>### Details</p>
<p>The issue is in `services/migrations/migrate.go`, in the migration allow/block-list check.</p>
<p>Current logic computes whether any resolved IP is allowed:</p>
<p>```go
var ipAllowed bool
var ipBlocked bool
for _, addr := range addrList {
    ipAllowed = ipAllowed || allowList.MatchIPAddr(addr)
    ipBlocked = ipBlocked || blockList.MatchIPAddr(addr)
}
```</p>
<p>Then, when an allow-list is active, the host is accepted if the hostname matches or `ipAllowed` is true:</p>
<p>```go
if !allowList.IsEmpty() {
    if !allowList.MatchHostName(hostName) &amp;&amp; !ipAllowed {
        return &amp;git.ErrInvalidCloneAddr{Host: hostName, IsPermissionDenied: true}
    }
}
```</p>
<p>This means a hostname resolving to both:</p>
<p>- an allowed public IP, e.g. `1.2.3.4`
- a blocked internal IP, e.g. `127.0.0.1`</p>
<p>passes validation because the public IP sets `ipAllowed =…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-h2x6-g7q6-344v"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</id>
    <title>WID-SEC-W-2026-2304 — Gitea: Mehrere Schwachstellen</title>
    <updated>2026-10-03T20:39:19.909669+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304"/>
  </entry>
</feed>
