<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 15:06:13 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-06150</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-06150</link>
      <description>bdu:2026-06150</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-06150</guid>
    </item>
    <item>
      <title>EUVD-2026-275154</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-275154</link>
      <description>EUVD-2026-275154</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-275154</guid>
    </item>
    <item>
      <title>fkie_cve-2026-26022</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-26022</link>
      <description>&lt;p&gt;Gogs is an open source self-hosted Git service. Prior to version 0.14.2, a stored cross-site scripting (XSS) vulnerability exists in the comment and issue description functionality. The application&amp;#39;s HTML sanitizer explicitly allows data: URI schemes, enabling authenticated users to inject arbitrary JavaScript execution via malicious links. This issue has been patched in version 0.14.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Gogs is an open source self-hosted Git service. Prior to version 0.14.2, a stored cross-site scripting (XSS) vulnerability exists in the comment and issue description functionality. The application&amp;#39;s HTML sanitizer explicitly allows data: URI schemes, enabling authenticated users to inject arbitrary JavaScript execution via malicious links. This issue has been patched in version 0.14.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-26022</guid>
    </item>
    <item>
      <title>GHSA-xrcr-gmf5-2r8j — Gogs: Stored XSS via data URI in issue comments</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xrcr-gmf5-2r8j</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: gogs.io/gogs&lt;/p&gt;
&lt;p&gt;### Summary
A Stored Cross-site Scripting (XSS) vulnerability exists in the comment and issue description functionality. The application&amp;#39;s HTML sanitizer explicitly allows `data:` URI schemes, enabling authenticated users to inject arbitrary JavaScript execution via malicious links.&lt;/p&gt;
&lt;p&gt;### Details
The vulnerability is located in `internal/markup/sanitizer.go`. The application uses the `bluemonday` HTML sanitizer but explicitly weakens the security policy by allowing the `data` URL scheme:&lt;/p&gt;
&lt;p&gt;```go
// internal/markup/sanitizer.go
func NewSanitizer() {
    sanitizer.init.Do(func() {
        // ...
        // Data URLs
        sanitizer.policy.AllowURLSchemes(&amp;#34;data&amp;#34;)
        // ...
    })
}
```&lt;/p&gt;
&lt;p&gt;While the Markdown renderer rewrites relative links (mitigating standard Markdown `[link](data:...)` attacks), Gogs supports **Raw HTML** input. Raw HTML anchor tags bypass the Markdown parser&amp;#39;s link rewriting and are processed directly by the sanitizer. Since the sanitizer is configured to allow `data:` URIs, payloads like `&amp;lt;a href=&amp;#34;data:text/html...&amp;#34;&amp;gt;` are rendered as-is.&lt;/p&gt;
&lt;p&gt;### PoC
1.  Create a file named `exploit.md` in a repository.
2.  Add the following content (Raw HTML):
    ```html
    &amp;lt;a href=&amp;#34;data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4=&amp;#34;&amp;gt;Click me for XSS&amp;lt;/a&amp;gt;
    ```
3.  Commit and push the file.
4.  Navigate to the file in the Gogs web interface.
5.  Click the &amp;#34;Click me for XSS&amp;#34; link.
6.  **Result:** An alert box with &amp;#34;XSS&amp;#34; appears, executing the JavaScript payloa…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: gogs.io/gogs&lt;/p&gt;
&lt;p&gt;### Summary
A Stored Cross-site Scripting (XSS) vulnerability exists in the comment and issue description functionality. The application&amp;#39;s HTML sanitizer explicitly allows `data:` URI schemes, enabling authenticated users to inject arbitrary JavaScript execution via malicious links.&lt;/p&gt;
&lt;p&gt;### Details
The vulnerability is located in `internal/markup/sanitizer.go`. The application uses the `bluemonday` HTML sanitizer but explicitly weakens the security policy by allowing the `data` URL scheme:&lt;/p&gt;
&lt;p&gt;```go
// internal/markup/sanitizer.go
func NewSanitizer() {
    sanitizer.init.Do(func() {
        // ...
        // Data URLs
        sanitizer.policy.AllowURLSchemes(&amp;#34;data&amp;#34;)
        // ...
    })
}
```&lt;/p&gt;
&lt;p&gt;While the Markdown renderer rewrites relative links (mitigating standard Markdown `[link](data:...)` attacks), Gogs supports **Raw HTML** input. Raw HTML anchor tags bypass the Markdown parser&amp;#39;s link rewriting and are processed directly by the sanitizer. Since the sanitizer is configured to allow `data:` URIs, payloads like `&amp;lt;a href=&amp;#34;data:text/html...&amp;#34;&amp;gt;` are rendered as-is.&lt;/p&gt;
&lt;p&gt;### PoC
1.  Create a file named `exploit.md` in a repository.
2.  Add the following content (Raw HTML):
    ```html
    &amp;lt;a href=&amp;#34;data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4=&amp;#34;&amp;gt;Click me for XSS&amp;lt;/a&amp;gt;
    ```
3.  Commit and push the file.
4.  Navigate to the file in the Gogs web interface.
5.  Click the &amp;#34;Click me for XSS&amp;#34; link.
6.  **Result:** An alert box with &amp;#34;XSS&amp;#34; appears, executing the JavaScript payloa…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xrcr-gmf5-2r8j</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0623 — Gogs: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0623</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gogs ausnutzen, um Daten zu manipulieren, Cross-Site-Scripting-Angriffe durchzuführen oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gogs ausnutzen, um Daten zu manipulieren, Cross-Site-Scripting-Angriffe durchzuführen oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0623</guid>
    </item>
  </channel>
</rss>
