<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T00:01:27.907186+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-352862</id>
    <title>EUVD-2026-352862</title>
    <updated>2026-10-04T00:01:27.971263+00:00</updated>
    <content>EUVD-2026-352862</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-352862"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-59765</id>
    <title>fkie_cve-2026-59765</title>
    <updated>2026-10-04T00:01:27.971308+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-59765"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2wm4-vwp6-v7xc</id>
    <title>GHSA-2wm4-vwp6-v7xc — Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata</title>
    <updated>2026-10-04T00:01:27.971356+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: code.gitea.io/gitea, Go: gitea.dev</p>
<p>### Summary</p>
<p>Gitea has robust SSRF protection via `hostmatcher.NewDialContext()` for webhook and migration clone URLs, which validates resolved IPs at the TCP dial level. However, three code paths use raw `http.Get()` (Go's `DefaultClient`) which completely bypasses this protection, enabling SSRF to internal services and local file read via the `file://` scheme.</p>
<p>### Vulnerable Code</p>
<p>**File: `modules/uri/uri.go` (line 32) -- Core vulnerability**</p>
<p>```go
func Open(uriStr string) (io.ReadCloser, error) {
    u, err := url.Parse(uriStr)
    switch strings.ToLower(u.Scheme) {
    case "http", "https":
        f, err := http.Get(uriStr)   // RAW http.Get -- no hostmatcher filtering
        return f.Body, nil
    case "file":
        return os.Open(u.Path)        // LOCAL FILE READ via file:// scheme
    }
}
```</p>
<p>**Callers in migration path:**
- `services/migrations/gitea_uploader.go:340` -- `uri.Open(*asset.DownloadURL)` for release assets
- `services/migrations/gitea_uploader.go:586` -- `uri.Open(pr.PatchURL)` for PR patches</p>
<p>**File: `services/migrations/dump.go` (lines 312, 453)**</p>
<p>```go
// Line 312 -- release asset download
resp, err := http.Get(*asset.DownloadURL)</p>
<p>// Line 453 -- PR patch download (with self-documenting TODO)
resp, err := http.Get(u) // TODO: This probably needs to use the downloader
```</p>
<p>**File: `routers/web/auth/oauth.go` (line 306)**</p>
<p>```go
func oauth2UpdateAvatarIfNeed(ctx *context.Context, url string, u *user_model.User) {
    resp, err := http.Get(url)…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2wm4-vwp6-v7xc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</id>
    <title>WID-SEC-W-2026-2304 — Gitea: Mehrere Schwachstellen</title>
    <updated>2026-10-04T00:01:27.971420+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304"/>
  </entry>
</feed>
