<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T22:31:38.132188+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-374338</id>
    <title>EUVD-2026-374338</title>
    <updated>2026-10-06T22:31:38.134423+00:00</updated>
    <content>EUVD-2026-374338</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-374338"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-61833</id>
    <title>fkie_cve-2026-61833</title>
    <updated>2026-10-06T22:31:38.134454+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>zot is a container image and artifact registry based on the Open Container Initiative Distribution Specification. Prior to 2.1.18, the bearer authentication handler in pkg/api/authn.go maps every HTTP method other than GET and HEAD to the push action, so DELETE requests are not checked for the distinct delete permission. Bearer-authenticated requests also bypass the fine-grained DistSpecAuthzHandler path in pkg/api/authz.go, while DeleteManifest and DeleteBlob perform no independent delete-permission check. A remote attacker with a bearer token limited to pull and push actions can therefore delete manifests and blobs within the token's repository scope, making images unavailable and allowing repository history to be altered despite the token lacking delete authorization. This issue is fixed in version 2.1.18.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-61833"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qg67-7m6v-qg25</id>
    <title>GHSA-qg67-7m6v-qg25 — zot: Bearer authentication maps DELETE to push scope, allowing unauthorized deletion</title>
    <updated>2026-10-06T22:31:38.134489+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: zotregistry.dev/zot/v2</p>
<p>### Summary</p>
<p>A bearer token with only `pull` and `push` scopes can successfully delete manifests and blobs from a zot registry. The bearer authentication handler maps all non-GET/HEAD HTTP methods, including DELETE, to the `"push"` action, and the `DistSpecAuthzHandler` middleware is bypassed entirely for bearer-authenticated requests. This allows any client holding a push-only bearer token to delete arbitrary manifests and blobs within the token's repository scope, in violation of the [Docker Distribution Token Authentication Specification](https://distribution.github.io/distribution/spec/auth/scope/).</p>
<p>### Details</p>
<p>The vulnerability exists in two interacting components:</p>
<p>**1. Action Mapping Collapse (`pkg/api/authn.go:571–586`)**</p>
<p>The bearer authentication handler maps HTTP methods to token scope actions using a binary check:</p>
<p>```go
action := "pull"
if m := request.Method; m != http.MethodGet &amp;&amp; m != http.MethodHead {
    action = "push"
}
```</p>
<p>This collapses DELETE, PUT, PATCH, and POST into a single `"push"` action. The `"delete"` action is never assigned.</p>
<p>**2. Authorization Bypass for Bearer Auth (`pkg/api/authz.go:270–275, 318–323`)**</p>
<p>When a request is authenticated via bearer token, the `DistSpecAuthzHandler` middleware, which performs fine-grained action inference (distinguishing `create`, `read`, `update`, and `delete`) is bypassed entirely:</p>
<p>```go
if err != nil || (authnMwCtx != nil &amp;&amp; authnMwCtx.AuthnType == BEARER) {
    next.ServeHTTP(response, request)
    re…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qg67-7m6v-qg25"/>
  </entry>
</feed>
