<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 22:42:00 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-10836</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-10836</link>
      <description>bdu:2026-10836</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-10836</guid>
    </item>
    <item>
      <title>EUVD-2026-333352</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-333352</link>
      <description>EUVD-2026-333352</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-333352</guid>
    </item>
    <item>
      <title>fkie_cve-2026-28699</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-28699</link>
      <description>&lt;p&gt;Gitea versions up to and including 1.26.1 allow OAuth2 access token scope enforcement to be bypassed through HTTP Basic authentication.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Gitea versions up to and including 1.26.1 allow OAuth2 access token scope enforcement to be bypassed through HTTP Basic authentication.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-28699</guid>
    </item>
    <item>
      <title>GHSA-9r5x-wg6m-x2rc — Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9r5x-wg6m-x2rc</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Gitea fails to enforce OAuth2 access token scopes when the token is submitted via HTTP Basic authentication instead of a Bearer token. An OAuth2 application granted only `read:user` can use the same token as `Authorization: Basic base64(&amp;lt;token&amp;gt;:x-oauth-basic)` and perform write actions, including modifying profiles, adding email addresses, creating repositories, and deleting repositories as the authorizing user.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Root cause:** `services/auth/basic.go` accepts OAuth2 access tokens through the Basic auth path but does not store the token scope in the request context:&lt;/p&gt;
&lt;p&gt;```go
// services/auth/basic.go
if uid != 0 {
    store.GetData()[&amp;#34;LoginMethod&amp;#34;] = OAuth2TokenMethodName
    store.GetData()[&amp;#34;IsApiToken&amp;#34;] = true   // scope is NOT set
    return u, nil
}
```&lt;/p&gt;
&lt;p&gt;The scope enforcement middleware in `routers/api/v1/api.go` exits early when `ApiTokenScope` is absent:&lt;/p&gt;
&lt;p&gt;```go
// routers/api/v1/api.go — tokenRequiresScopes
scope, scopeExists := ctx.Data[&amp;#34;ApiTokenScope&amp;#34;].(auth_model.AccessTokenScope)
if ctx.Data[&amp;#34;IsApiToken&amp;#34;] != true || !scopeExists {
    return   //&amp;lt;- exits without checking scope, all actions permitted
}
```&lt;/p&gt;
&lt;p&gt;When a token arrives via Bearer, `ApiTokenScope` is populated and scope checks apply normally. When the same token arrives via Basic auth, `ApiTokenScope` is never set, so `tokenRequiresScopes` returns immediately and no scope is enforced.&lt;/p&gt;
&lt;p&gt;**Suggested fix:** When an OAuth2 access token is accepted in `services/auth/basic.go`, populate `A…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Gitea fails to enforce OAuth2 access token scopes when the token is submitted via HTTP Basic authentication instead of a Bearer token. An OAuth2 application granted only `read:user` can use the same token as `Authorization: Basic base64(&amp;lt;token&amp;gt;:x-oauth-basic)` and perform write actions, including modifying profiles, adding email addresses, creating repositories, and deleting repositories as the authorizing user.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Root cause:** `services/auth/basic.go` accepts OAuth2 access tokens through the Basic auth path but does not store the token scope in the request context:&lt;/p&gt;
&lt;p&gt;```go
// services/auth/basic.go
if uid != 0 {
    store.GetData()[&amp;#34;LoginMethod&amp;#34;] = OAuth2TokenMethodName
    store.GetData()[&amp;#34;IsApiToken&amp;#34;] = true   // scope is NOT set
    return u, nil
}
```&lt;/p&gt;
&lt;p&gt;The scope enforcement middleware in `routers/api/v1/api.go` exits early when `ApiTokenScope` is absent:&lt;/p&gt;
&lt;p&gt;```go
// routers/api/v1/api.go — tokenRequiresScopes
scope, scopeExists := ctx.Data[&amp;#34;ApiTokenScope&amp;#34;].(auth_model.AccessTokenScope)
if ctx.Data[&amp;#34;IsApiToken&amp;#34;] != true || !scopeExists {
    return   //&amp;lt;- exits without checking scope, all actions permitted
}
```&lt;/p&gt;
&lt;p&gt;When a token arrives via Bearer, `ApiTokenScope` is populated and scope checks apply normally. When the same token arrives via Basic auth, `ApiTokenScope` is never set, so `tokenRequiresScopes` returns immediately and no scope is enforced.&lt;/p&gt;
&lt;p&gt;**Suggested fix:** When an OAuth2 access token is accepted in `services/auth/basic.go`, populate `A…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9r5x-wg6m-x2rc</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1637 — Gitea: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1637</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um möglicherweise erweiterte Privilegien zu erlangen, Sicherheitsmaßnahmen zu umgehen oder Daten zu manipulieren und offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um möglicherweise erweiterte Privilegien zu erlangen, Sicherheitsmaßnahmen zu umgehen oder Daten zu manipulieren und offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1637</guid>
    </item>
  </channel>
</rss>
