<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T06:12:42.281896+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-352869</id>
    <title>EUVD-2026-352869</title>
    <updated>2026-10-04T06:12:42.284725+00:00</updated>
    <content>EUVD-2026-352869</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-352869"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-58445</id>
    <title>fkie_cve-2026-58445</title>
    <updated>2026-10-04T06:12:42.284764+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-58445"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-pgqf-926r-548m</id>
    <title>GHSA-pgqf-926r-548m — Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API</title>
    <updated>2026-10-04T06:12:42.284796+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: code.gitea.io/gitea</p>
<p>## Summary</p>
<p>The API endpoint `DELETE /repos/{owner}/{repo}/issues/{index}/labels/{id}` loads the label by ID with a **global,
unscoped** lookup and never verifies the label belongs to the URL's repository (or its owning organization). Because
the response status differs by whether the label ID exists **anywhere on the instance** (204) versus not (422), an
authenticated user can use the endpoint as a **cross-repository label-ID existence / enumeration oracle**, including
for labels in repositories and organizations they cannot access.</p>
<p>## Severity</p>
<p>- The leaked information is minimal (existence/count of label IDs instance-wide); **no label name, color, or owning
  repository is disclosed, and no cross-repository write occurs.**</p>
<p>## Affected / patched versions</p>
<p>- **Affected:** through **1.26.3** (latest at time of report).
- **Patched:** none yet.</p>
<p>## Details</p>
<p>`DeleteIssueLabel` resolves the label with a global loader and never checks its scope:</p>
<p>```go
// routers/api/v1/repo/issue_label.go  (DeleteIssueLabel)
label, err := issues_model.GetLabelByID(ctx, ctx.PathParamInt64("id"))   // global, unscoped
```</p>
<p>`GetLabelByID` (`models/issues/label.go`) is `e.ID(labelID).Get(l)` with **no** `repo_id` / `org_id` filter. The
handler never verifies `label.RepoID == ctx.Repo.Repository.ID` (nor the org-label equivalent), and the downstream
`issue_service.RemoveLabel` (`services/issue/label.go`) only re-checks the doer's write permission on the **issue's
own** repository — never that the…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-pgqf-926r-548m"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</id>
    <title>WID-SEC-W-2026-2304 — Gitea: Mehrere Schwachstellen</title>
    <updated>2026-10-04T06:12:42.284861+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304"/>
  </entry>
</feed>
