<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 23:42:46 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-10563</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-10563</link>
      <description>bdu:2026-10563</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-10563</guid>
    </item>
    <item>
      <title>EUVD-2026-333353</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-333353</link>
      <description>EUVD-2026-333353</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-333353</guid>
    </item>
    <item>
      <title>fkie_cve-2026-27783</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-27783</link>
      <description>&lt;p&gt;Gitea versions up to and including 1.26.1 do not enforce repository-unit authorization on issue-template API endpoints.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Gitea versions up to and including 1.26.1 do not enforce repository-unit authorization on issue-template API endpoints.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-27783</guid>
    </item>
    <item>
      <title>GHSA-3fwp-p5rj-2pxf — Gitea: Missing repository-unit authorization on issue-template API endpoints</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3fwp-p5rj-2pxf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Three Gitea API endpoints — `GET /repos/{owner}/{repo}/issue_templates`,
`GET /repos/{owner}/{repo}/issue_config` and `GET /repos/{owner}/{repo}/issue_config/validate`
— read files from the repository&amp;#39;s **Code** default branch (`.gitea/ISSUE_TEMPLATE/*`
and `issue_config.yaml`) and return their contents, but are registered **without**
the `reqRepoReader(unit.TypeCode)` authorization middleware that every sibling
Code-tree endpoint in the same route group carries.&lt;/p&gt;
&lt;p&gt;A user who has access to a private repository through *any single repository unit*
(for example an organization team granted only the **Issues** unit, with no Code
access) can therefore read the issue-template and issue-config files of that
repository&amp;#39;s Code tree, which their permission set should not expose.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Root cause&lt;/p&gt;
&lt;p&gt;### The three endpoints lack the unit guard&lt;/p&gt;
&lt;p&gt;`routers/api/v1/api.go:1433-1437`:&lt;/p&gt;
&lt;p&gt;m.Get(&amp;#34;/issue_templates&amp;#34;, context.ReferencesGitRepo(), repo.GetIssueTemplates)
    m.Get(&amp;#34;/issue_config&amp;#34;, context.ReferencesGitRepo(), repo.GetIssueConfig)
    m.Get(&amp;#34;/issue_config/validate&amp;#34;, context.ReferencesGitRepo(), repo.ValidateIssueConfig)
    m.Get(&amp;#34;/languages&amp;#34;, reqRepoReader(unit.TypeCode), repo.GetLanguages)
    m.Get(&amp;#34;/licenses&amp;#34;, reqRepoReader(unit.TypeCode), repo.GetLicenses)&lt;/p&gt;
&lt;p&gt;`context.ReferencesGitRepo()` only opens the git repository — it performs no
permission check. Every other endpoint in this group that reads Code-tree content
is guarded with `reqRepoReader(unit.TypeCode)`: `/…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Three Gitea API endpoints — `GET /repos/{owner}/{repo}/issue_templates`,
`GET /repos/{owner}/{repo}/issue_config` and `GET /repos/{owner}/{repo}/issue_config/validate`
— read files from the repository&amp;#39;s **Code** default branch (`.gitea/ISSUE_TEMPLATE/*`
and `issue_config.yaml`) and return their contents, but are registered **without**
the `reqRepoReader(unit.TypeCode)` authorization middleware that every sibling
Code-tree endpoint in the same route group carries.&lt;/p&gt;
&lt;p&gt;A user who has access to a private repository through *any single repository unit*
(for example an organization team granted only the **Issues** unit, with no Code
access) can therefore read the issue-template and issue-config files of that
repository&amp;#39;s Code tree, which their permission set should not expose.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Root cause&lt;/p&gt;
&lt;p&gt;### The three endpoints lack the unit guard&lt;/p&gt;
&lt;p&gt;`routers/api/v1/api.go:1433-1437`:&lt;/p&gt;
&lt;p&gt;m.Get(&amp;#34;/issue_templates&amp;#34;, context.ReferencesGitRepo(), repo.GetIssueTemplates)
    m.Get(&amp;#34;/issue_config&amp;#34;, context.ReferencesGitRepo(), repo.GetIssueConfig)
    m.Get(&amp;#34;/issue_config/validate&amp;#34;, context.ReferencesGitRepo(), repo.ValidateIssueConfig)
    m.Get(&amp;#34;/languages&amp;#34;, reqRepoReader(unit.TypeCode), repo.GetLanguages)
    m.Get(&amp;#34;/licenses&amp;#34;, reqRepoReader(unit.TypeCode), repo.GetLicenses)&lt;/p&gt;
&lt;p&gt;`context.ReferencesGitRepo()` only opens the git repository — it performs no
permission check. Every other endpoint in this group that reads Code-tree content
is guarded with `reqRepoReader(unit.TypeCode)`: `/…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3fwp-p5rj-2pxf</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1637 — Gitea: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1637</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um möglicherweise erweiterte Privilegien zu erlangen, Sicherheitsmaßnahmen zu umgehen oder Daten zu manipulieren und offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um möglicherweise erweiterte Privilegien zu erlangen, Sicherheitsmaßnahmen zu umgehen oder Daten zu manipulieren und offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1637</guid>
    </item>
  </channel>
</rss>
