<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 08:25:01 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-333526</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-333526</link>
      <description>EUVD-2026-333526</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-333526</guid>
    </item>
    <item>
      <title>fkie_cve-2026-22555</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-22555</link>
      <description>&lt;p&gt;Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCreateOrgRepo check, which can expose organization secrets.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCreateOrgRepo check, which can expose organization secrets.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-22555</guid>
    </item>
    <item>
      <title>GHSA-fhx7-m96w-mv29 — Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fhx7-m96w-mv29</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The API endpoint `POST /api/v1/repos/{owner}/{repo}/forks` only checks `IsOrgMember()` when a user forks a repository into an organization, but does not check `CanCreateOrgRepo()`. The web UI fork handler correctly checks both. This allows a read-only organization member — in a team with `can_create_org_repo=false` — to create repositories in the organization namespace via the API. The attacker receives full admin permissions on the forked repository, can enable Actions, push arbitrary workflow files, and exfiltrate all organization-level CI/CD secrets (deploy keys, cloud credentials, API tokens) through the runner infrastructure.&lt;/p&gt;
&lt;p&gt;## Steps To Reproduce&lt;/p&gt;
&lt;p&gt;### 1. Environment setup&lt;/p&gt;
&lt;p&gt;Start a Gitea instance with Actions enabled:&lt;/p&gt;
&lt;p&gt;```bash
# docker-compose.yml
cat &amp;gt; docker-compose.yml &amp;lt;&amp;lt; &amp;#39;EOF&amp;#39;
version: &amp;#39;3&amp;#39;
services:
  gitea:
    image: gitea/gitea:1.23
    container_name: gitea-poc
    ports:
      - &amp;#34;3000:3000&amp;#34;
    volumes:
      - gitea-data:/data
    environment:
      - GITEA__database__DB_TYPE=sqlite3
      - GITEA__server__ROOT_URL=http://localhost:3000/
      - GITEA__security__INSTALL_LOCK=true
      - GITEA__actions__ENABLED=true
volumes:
  gitea-data:
EOF&lt;/p&gt;
&lt;p&gt;docker compose up -d
# Wait for startup
sleep 15&lt;/p&gt;
&lt;p&gt;# Create admin user
docker exec -u git gitea-poc gitea admin user create \
  --admin --username admin --password &amp;#39;Admin1234!&amp;#39; \
  --email admin@example.com --must-change-password=false
```&lt;/p&gt;
&lt;p&gt;### 2. Create the target environment (as admin)&lt;/p&gt;
&lt;p&gt;```bash
# Get admin…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The API endpoint `POST /api/v1/repos/{owner}/{repo}/forks` only checks `IsOrgMember()` when a user forks a repository into an organization, but does not check `CanCreateOrgRepo()`. The web UI fork handler correctly checks both. This allows a read-only organization member — in a team with `can_create_org_repo=false` — to create repositories in the organization namespace via the API. The attacker receives full admin permissions on the forked repository, can enable Actions, push arbitrary workflow files, and exfiltrate all organization-level CI/CD secrets (deploy keys, cloud credentials, API tokens) through the runner infrastructure.&lt;/p&gt;
&lt;p&gt;## Steps To Reproduce&lt;/p&gt;
&lt;p&gt;### 1. Environment setup&lt;/p&gt;
&lt;p&gt;Start a Gitea instance with Actions enabled:&lt;/p&gt;
&lt;p&gt;```bash
# docker-compose.yml
cat &amp;gt; docker-compose.yml &amp;lt;&amp;lt; &amp;#39;EOF&amp;#39;
version: &amp;#39;3&amp;#39;
services:
  gitea:
    image: gitea/gitea:1.23
    container_name: gitea-poc
    ports:
      - &amp;#34;3000:3000&amp;#34;
    volumes:
      - gitea-data:/data
    environment:
      - GITEA__database__DB_TYPE=sqlite3
      - GITEA__server__ROOT_URL=http://localhost:3000/
      - GITEA__security__INSTALL_LOCK=true
      - GITEA__actions__ENABLED=true
volumes:
  gitea-data:
EOF&lt;/p&gt;
&lt;p&gt;docker compose up -d
# Wait for startup
sleep 15&lt;/p&gt;
&lt;p&gt;# Create admin user
docker exec -u git gitea-poc gitea admin user create \
  --admin --username admin --password &amp;#39;Admin1234!&amp;#39; \
  --email admin@example.com --must-change-password=false
```&lt;/p&gt;
&lt;p&gt;### 2. Create the target environment (as admin)&lt;/p&gt;
&lt;p&gt;```bash
# Get admin…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fhx7-m96w-mv29</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1172 — Gitea: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1172</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um Informationen offenzulegen, um Sicherheitsvorkehrungen zu umgehen, und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um Informationen offenzulegen, um Sicherheitsvorkehrungen zu umgehen, und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1172</guid>
    </item>
  </channel>
</rss>
