<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 11:35:06 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-12013</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-12013</link>
      <description>bdu:2026-12013</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-12013</guid>
    </item>
    <item>
      <title>EUVD-2026-333741</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-333741</link>
      <description>EUVD-2026-333741</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-333741</guid>
    </item>
    <item>
      <title>fkie_cve-2026-27761</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-27761</link>
      <description>&lt;p&gt;Gitea versions up to and including 1.26.2 allow repository RSS and Atom feed endpoints to bypass API access token scope checks, exposing private repository commit data to tokens without the required repository scope.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Gitea versions up to and including 1.26.2 allow repository RSS and Atom feed endpoints to bypass API access token scope checks, exposing private repository commit data to tokens without the required repository scope.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-27761</guid>
    </item>
    <item>
      <title>GHSA-3pww-vcvm-3gmj — Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3pww-vcvm-3gmj</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;### Summary
A Gitea personal access token (PAT) restricted to a non-repository scope (e.g. `read:issue`) can read the commit history of any private repository the token owner can access, via the repository RSS/Atom feed endpoints. The same token is correctly denied (403) on `/raw`, `/media`, `/archive`, and the contents API. It leaks commit SHAs, full commit messages (which frequently contain secrets and internal context), and committer name + email.&lt;/p&gt;
&lt;p&gt;### Details
Gitea enforces PAT scope on repository-content endpoints via `checkDownloadTokenScope()` (added in PR #37698, extended to the archive endpoint by the CVE-2026-20706 fix in 1.26.2). The RSS/Atom feed handlers were never included: they (a) opt into PAT auth via `webAuth.AllowBasic`, (b) serve private-repo content, but (c) never call `checkDownloadTokenScope()`.&lt;/p&gt;
&lt;p&gt;Affected handlers (all carry `AllowBasic`, none call the scope check):
- `RenderBranchFeedRSS/Atom` - `routers/web/feed/render.go` (last 10 commits: SHA, title, full message, committer name + email)
- `ShowFileFeed` - `routers/web/feed/file.go` (per-file commit history)
- repo activity feed `/{owner}/{repo}.rss` / `.atom`
- `TagsListFeedRSS/Atom`, `ReleasesFeedRSS/Atom` - `routers/web/repo/release.go`&lt;/p&gt;
&lt;p&gt;Root cause: `routers/web/web.go` registers the feed routes with `webAuth.AllowBasic` so a PAT authenticates, but the unit-permission middleware only checks the user&amp;#39;s access, not the token&amp;#39;s scope. `checkDownloadTokenScope` (`routers/web/repo/download.go` and th…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;### Summary
A Gitea personal access token (PAT) restricted to a non-repository scope (e.g. `read:issue`) can read the commit history of any private repository the token owner can access, via the repository RSS/Atom feed endpoints. The same token is correctly denied (403) on `/raw`, `/media`, `/archive`, and the contents API. It leaks commit SHAs, full commit messages (which frequently contain secrets and internal context), and committer name + email.&lt;/p&gt;
&lt;p&gt;### Details
Gitea enforces PAT scope on repository-content endpoints via `checkDownloadTokenScope()` (added in PR #37698, extended to the archive endpoint by the CVE-2026-20706 fix in 1.26.2). The RSS/Atom feed handlers were never included: they (a) opt into PAT auth via `webAuth.AllowBasic`, (b) serve private-repo content, but (c) never call `checkDownloadTokenScope()`.&lt;/p&gt;
&lt;p&gt;Affected handlers (all carry `AllowBasic`, none call the scope check):
- `RenderBranchFeedRSS/Atom` - `routers/web/feed/render.go` (last 10 commits: SHA, title, full message, committer name + email)
- `ShowFileFeed` - `routers/web/feed/file.go` (per-file commit history)
- repo activity feed `/{owner}/{repo}.rss` / `.atom`
- `TagsListFeedRSS/Atom`, `ReleasesFeedRSS/Atom` - `routers/web/repo/release.go`&lt;/p&gt;
&lt;p&gt;Root cause: `routers/web/web.go` registers the feed routes with `webAuth.AllowBasic` so a PAT authenticates, but the unit-permission middleware only checks the user&amp;#39;s access, not the token&amp;#39;s scope. `checkDownloadTokenScope` (`routers/web/repo/download.go` and th…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3pww-vcvm-3gmj</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2027 — Gitea: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2027</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um erweiterte Berechtigungen zu erlangen, sich als Benutzer auszugeben, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren und vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um erweiterte Berechtigungen zu erlangen, sich als Benutzer auszugeben, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren und vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2027</guid>
    </item>
  </channel>
</rss>
