<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T11:03:31.600291+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-352917</id>
    <title>EUVD-2026-352917</title>
    <updated>2026-10-02T11:03:31.619748+00:00</updated>
    <content>EUVD-2026-352917</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-352917"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-58440</id>
    <title>fkie_cve-2026-58440</title>
    <updated>2026-10-02T11:03:31.619783+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-58440"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-66m4-5jjr-2rg5</id>
    <title>GHSA-66m4-5jjr-2rg5 — Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltrati…</title>
    <updated>2026-10-02T11:03:31.619816+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: gitea.dev</p>
<p>## Affected product
Gitea — `services/repository/collaboration.go` (`DeleteCollaboration`) + webhook delivery</p>
<p>## Summary
When a collaborator with admin permission on a private repo creates a webhook, that webhook keeps firing
after the collaborator's access is revoked. Gitea's revocation cleanup `DeleteCollaboration` removes the
collaboration record, recalculates accesses, drops watches, and unassigns issues — but it does **not**
remove or disable webhooks the user created, and webhook delivery never re-checks whether the creator still
has repo access. The former collaborator therefore receives the full payload (issue/comment bodies, commit
data) of all future repository events at their controlled endpoint, indefinitely and invisibly.</p>
<p>## Affected code
- `services/repository/collaboration.go` → `DeleteCollaboration()` — cleans watches/assignees only; no
  webhook cleanup.
- Webhook delivery path — fires on repo events without re-validating the creator's current access.</p>
<p>## Steps to reproduce
Using the provided reproduction materials:
1. Attacker (admin collaborator) creates a webhook → revoke access.
2. Control: `GET /api/v1/repos/admin/wh-repo` (attacker) → **404**.
3. `GET .../hooks` → webhook still `active=true`.
4. Admin creates a new issue **after** revocation → the catcher receives `action:"opened"`,
   `issue.title:"CRITICAL SECRET: …"`, `issue.body` (sentinel private key), `repository.private:true`.
(Runtime-confirmed on `gitea/gitea:1.25.4`. Catcher is an internal…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-66m4-5jjr-2rg5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</id>
    <title>WID-SEC-W-2026-2304 — Gitea: Mehrere Schwachstellen</title>
    <updated>2026-10-02T11:03:31.619866+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304"/>
  </entry>
</feed>
