<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T13:00:03.929920+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-352914</id>
    <title>EUVD-2026-352914</title>
    <updated>2026-10-04T13:00:03.977794+00:00</updated>
    <content>EUVD-2026-352914</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-352914"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-58443</id>
    <title>fkie_cve-2026-58443</title>
    <updated>2026-10-04T13:00:03.977832+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Public-only repository tokens can update private PR head branches</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-58443"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xxjv-752h-3vp2</id>
    <title>GHSA-xxjv-752h-3vp2 — Gitea: Public-only repository tokens can update private PR head branches</title>
    <updated>2026-10-04T13:00:03.977864+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: code.gitea.io/gitea</p>
<p>### Summary
Gitea allows a `public-only,write:repository` token to update a private pull request head branch through a public base repository route.</p>
<p>The vulnerable endpoint is:</p>
<p>```text
POST /api/v1/repos/{public-owner}/{public-repo}/pulls/{index}/update
```</p>
<p>Gitea checks the token's public-only restriction against the route repository, which is the public base repository. `UpdatePullRequest()` then authorizes the pull request head repository with ordinary user RBAC and calls the pull update service. If the head repository is private, the active token's public-only restriction is not re-applied to that private repository before Gitea pushes changes into it.</p>
<p>As a result, the same token that cannot directly write to the private repository can still cause Gitea to push public base commits into the private head branch.</p>
<p>### Details
The pull request API routes are attached under a repository route group. The public-only check applies to `ctx.Repo.Repository`, the route/base repository.</p>
<p>```go
// routers/api/v1/api.go:1358-1394
					m.Group("/pulls", func() {
						m.Combo("").Get(repo.ListPullRequests).
							Post(reqToken(), mustNotBeArchived, bind(api.CreatePullRequestOption{}), repo.CreatePullRequest)
						m.Get("/pinned", repo.ListPinnedPullRequests)
						m.Post("/comments/{id}/resolve", reqToken(), mustNotBeArchived, repo.ResolvePullReviewComment)
						m.Post("/comments/{id}/unresolve", reqToken(), mustNotBeArchived, repo.UnresolvePullReviewComment)
						m.Group("/{in…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xxjv-752h-3vp2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</id>
    <title>WID-SEC-W-2026-2304 — Gitea: Mehrere Schwachstellen</title>
    <updated>2026-10-04T13:00:03.977952+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304"/>
  </entry>
</feed>
