<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 16:21:33 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-352310</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352310</link>
      <description>EUVD-2026-352310</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352310</guid>
    </item>
    <item>
      <title>fkie_cve-2026-42931</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42931</link>
      <description>&lt;p&gt;Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-42931</guid>
    </item>
    <item>
      <title>GHSA-wwqq-x6w4-frm2 — Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wwqq-x6w4-frm2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;### Summary
An unbounded `io.ReadAll(ctx.Req.Body)` call in the NPM package tag API endpoint allows any authenticated user to crash the Gitea server by sending a single large HTTP request. The request body is read entirely into memory with no size limit, causing an Out-of-Memory (OOM) kill. With concurrent requests, the attack produces a persistent denial of service that survives automatic restarts.&lt;/p&gt;
&lt;p&gt;### Details
The [`AddPackageTag`](https://github.com/go-gitea/gitea/blob/a12f9807933bd463368c6111dbc283d8a65f20f7/routers/api/packages/npm/npm.go#L336) function reads the entire HTTP request body into memory using `io.ReadAll()` with no size validation:&lt;/p&gt;
&lt;p&gt;```go
// routers/api/packages/npm/npm.go:332-341
func AddPackageTag(ctx *context.Context) {
    packageName := packageNameFromParams(ctx)&lt;/p&gt;
&lt;p&gt;body, err := io.ReadAll(ctx.Req.Body)  // NO SIZE LIMIT
    if err != nil {
        apiError(ctx, http.StatusInternalServerError, err)
        return
    }
    version := strings.Trim(string(body), &amp;#34;\&amp;#34;&amp;#34;)
    // ...
}
```&lt;/p&gt;
&lt;p&gt;This route is registered at [`routers/api/packages/api.go:433`](https://github.com/go-gitea/gitea/blob/a12f9807933bd463368c6111dbc283d8a65f20f7/routers/api/packages/api.go#L433):
```go
r.Group(&amp;#34;/-/package/{id}/dist-tags&amp;#34;, func() {
    // ...
    r.Group(&amp;#34;/{tag}&amp;#34;, func() {
        r.Put(&amp;#34;&amp;#34;, npm.AddPackageTag)    // reqPackageAccess(perm.AccessModeWrite)
        r.Delete(&amp;#34;&amp;#34;, npm.DeletePackageTag)
    })
})
```&lt;/p&gt;
&lt;p&gt;**Why this causes OOM and not just a slow request:**&lt;/p&gt;
&lt;p&gt;In Go, `…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;### Summary
An unbounded `io.ReadAll(ctx.Req.Body)` call in the NPM package tag API endpoint allows any authenticated user to crash the Gitea server by sending a single large HTTP request. The request body is read entirely into memory with no size limit, causing an Out-of-Memory (OOM) kill. With concurrent requests, the attack produces a persistent denial of service that survives automatic restarts.&lt;/p&gt;
&lt;p&gt;### Details
The [`AddPackageTag`](https://github.com/go-gitea/gitea/blob/a12f9807933bd463368c6111dbc283d8a65f20f7/routers/api/packages/npm/npm.go#L336) function reads the entire HTTP request body into memory using `io.ReadAll()` with no size validation:&lt;/p&gt;
&lt;p&gt;```go
// routers/api/packages/npm/npm.go:332-341
func AddPackageTag(ctx *context.Context) {
    packageName := packageNameFromParams(ctx)&lt;/p&gt;
&lt;p&gt;body, err := io.ReadAll(ctx.Req.Body)  // NO SIZE LIMIT
    if err != nil {
        apiError(ctx, http.StatusInternalServerError, err)
        return
    }
    version := strings.Trim(string(body), &amp;#34;\&amp;#34;&amp;#34;)
    // ...
}
```&lt;/p&gt;
&lt;p&gt;This route is registered at [`routers/api/packages/api.go:433`](https://github.com/go-gitea/gitea/blob/a12f9807933bd463368c6111dbc283d8a65f20f7/routers/api/packages/api.go#L433):
```go
r.Group(&amp;#34;/-/package/{id}/dist-tags&amp;#34;, func() {
    // ...
    r.Group(&amp;#34;/{tag}&amp;#34;, func() {
        r.Put(&amp;#34;&amp;#34;, npm.AddPackageTag)    // reqPackageAccess(perm.AccessModeWrite)
        r.Delete(&amp;#34;&amp;#34;, npm.DeletePackageTag)
    })
})
```&lt;/p&gt;
&lt;p&gt;**Why this causes OOM and not just a slow request:**&lt;/p&gt;
&lt;p&gt;In Go, `…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wwqq-x6w4-frm2</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2304 — Gitea: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</guid>
    </item>
  </channel>
</rss>
