<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 22:45:06 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-333747</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-333747</link>
      <description>EUVD-2026-333747</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-333747</guid>
    </item>
    <item>
      <title>fkie_cve-2026-26231</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-26231</link>
      <description>&lt;p&gt;Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to repositories that the user can read but should not be able to write.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to repositories that the user can read but should not be able to write.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-26231</guid>
    </item>
    <item>
      <title>GHSA-mm7c-rhg6-qr4r — Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mm7c-rhg6-qr4r</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Any authenticated low-privilege user with read access to a repository can push arbitrary commits directly to that repository, bypassing all write-access checks.&lt;/p&gt;
&lt;p&gt;## Vulnerability&lt;/p&gt;
&lt;p&gt;Gitea&amp;#39;s &amp;#34;Allow edits from maintainers&amp;#34; PR option can be abused via reverse-fork PRs:&lt;/p&gt;
&lt;p&gt;1. The web UI PR-create endpoint binds `allow_maintainer_edit=true` **without** verifying that the submitter has write access to the HEAD repository.
2. Gitea allows creating a PR where **BASE = attacker&amp;#39;s fork** and **HEAD = upstream target**. The attacker is &amp;#34;maintainer&amp;#34; of the BASE (their own fork), so the flag is set against the upstream HEAD.
3. On `git push` over HTTP/SSH, Gitea relaxes the required access mode to `Read` when `SupportProcReceive` is enabled ([`routers/web/repo/githttp.go`](https://github.com/go-gitea/gitea/blob/v1.25.5/routers/web/repo/githttp.go#L189), [`routers/private/serv.go`](https://github.com/go-gitea/gitea/blob/v1.25.5/routers/private/serv.go#L337)) and defers enforcement to the pre-receive hook.
4. The pre-receive hook calls [`CanMaintainerWriteToBranch`](https://github.com/go-gitea/gitea/blob/v1.25.5/models/issues/pull_list.go#L72) (`models/issues/pull_list.go`), which finds the malicious PR, sees `AllowMaintainerEdit=true`, and checks whether the pusher has write access to the **BASE** repo. Since BASE is the attacker&amp;#39;s own fork, the check passes and the push is authorized against the upstream.&lt;/p&gt;
&lt;p&gt;## Exploitation&lt;/p&gt;
&lt;p&gt;1. Attacker forks the target repository.
2. Attacker visi…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Any authenticated low-privilege user with read access to a repository can push arbitrary commits directly to that repository, bypassing all write-access checks.&lt;/p&gt;
&lt;p&gt;## Vulnerability&lt;/p&gt;
&lt;p&gt;Gitea&amp;#39;s &amp;#34;Allow edits from maintainers&amp;#34; PR option can be abused via reverse-fork PRs:&lt;/p&gt;
&lt;p&gt;1. The web UI PR-create endpoint binds `allow_maintainer_edit=true` **without** verifying that the submitter has write access to the HEAD repository.
2. Gitea allows creating a PR where **BASE = attacker&amp;#39;s fork** and **HEAD = upstream target**. The attacker is &amp;#34;maintainer&amp;#34; of the BASE (their own fork), so the flag is set against the upstream HEAD.
3. On `git push` over HTTP/SSH, Gitea relaxes the required access mode to `Read` when `SupportProcReceive` is enabled ([`routers/web/repo/githttp.go`](https://github.com/go-gitea/gitea/blob/v1.25.5/routers/web/repo/githttp.go#L189), [`routers/private/serv.go`](https://github.com/go-gitea/gitea/blob/v1.25.5/routers/private/serv.go#L337)) and defers enforcement to the pre-receive hook.
4. The pre-receive hook calls [`CanMaintainerWriteToBranch`](https://github.com/go-gitea/gitea/blob/v1.25.5/models/issues/pull_list.go#L72) (`models/issues/pull_list.go`), which finds the malicious PR, sees `AllowMaintainerEdit=true`, and checks whether the pusher has write access to the **BASE** repo. Since BASE is the attacker&amp;#39;s own fork, the check passes and the push is authorized against the upstream.&lt;/p&gt;
&lt;p&gt;## Exploitation&lt;/p&gt;
&lt;p&gt;1. Attacker forks the target repository.
2. Attacker visi…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mm7c-rhg6-qr4r</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1637 — Gitea: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1637</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um möglicherweise erweiterte Privilegien zu erlangen, Sicherheitsmaßnahmen zu umgehen oder Daten zu manipulieren und offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um möglicherweise erweiterte Privilegien zu erlangen, Sicherheitsmaßnahmen zu umgehen oder Daten zu manipulieren und offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1637</guid>
    </item>
  </channel>
</rss>
