<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 20:37:50 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-352923</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352923</link>
      <description>EUVD-2026-352923</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352923</guid>
    </item>
    <item>
      <title>fkie_cve-2026-50105</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-50105</link>
      <description>&lt;p&gt;RSS/Atom feed handlers bypass API-token scope &amp;amp; public-only confinement (incomplete fix of #37698)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;RSS/Atom feed handlers bypass API-token scope &amp;amp; public-only confinement (incomplete fix of #37698)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-50105</guid>
    </item>
    <item>
      <title>GHSA-6cqf-375w-639g — Gitea: RSS/Atom feed handlers bypass API-token scope &amp; public-only confinement (incomplete fix of #37698)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6cqf-375w-639g</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Gitea&amp;#39;s RSS/Atom feed handlers accept API-token Basic auth but perform **no token-scope or
public-only enforcement**. A personal access token that is correctly blocked (HTTP 403) from a
private repository on `/raw`, `/media`, `/archive`, and `/releases/download/...` — because it is
marked *public-only* or lacks the `repository` scope category — still returns that repository&amp;#39;s
private content through the feed routes. This is a token-confinement bypass and appears to be an
incomplete fix of #37698, which added that scope enforcement to the download handlers but not to the
sibling feed handlers.&lt;/p&gt;
&lt;p&gt;This is **not** a cross-user access bug: the requesting account must still legitimately have repo
read access (`RepoAssignment` + `reqUnitCodeReader` are enforced). What is bypassed is the guarantee
that a *confined* token cannot reach private content — which is exactly the property #37698 was
shipped to provide for downloads, and which matters when such a token is handed to a third-party
service/CI, leaked, or used in a lower-trust integration.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;#37698 added `context.CheckTokenScopes` / `CheckRepoScopedToken`
(`services/context/permission.go`) to the raw / media / archive / attachment download handlers, so a
public-only or wrong-scope-category token cannot read private-repo content even when the owning user
otherwise has access.&lt;/p&gt;
&lt;p&gt;The feed handlers are registered with `webAuth.AllowBasic` (so they accept token Basic auth) but call
no scope / public-only check.…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Gitea&amp;#39;s RSS/Atom feed handlers accept API-token Basic auth but perform **no token-scope or
public-only enforcement**. A personal access token that is correctly blocked (HTTP 403) from a
private repository on `/raw`, `/media`, `/archive`, and `/releases/download/...` — because it is
marked *public-only* or lacks the `repository` scope category — still returns that repository&amp;#39;s
private content through the feed routes. This is a token-confinement bypass and appears to be an
incomplete fix of #37698, which added that scope enforcement to the download handlers but not to the
sibling feed handlers.&lt;/p&gt;
&lt;p&gt;This is **not** a cross-user access bug: the requesting account must still legitimately have repo
read access (`RepoAssignment` + `reqUnitCodeReader` are enforced). What is bypassed is the guarantee
that a *confined* token cannot reach private content — which is exactly the property #37698 was
shipped to provide for downloads, and which matters when such a token is handed to a third-party
service/CI, leaked, or used in a lower-trust integration.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;#37698 added `context.CheckTokenScopes` / `CheckRepoScopedToken`
(`services/context/permission.go`) to the raw / media / archive / attachment download handlers, so a
public-only or wrong-scope-category token cannot read private-repo content even when the owning user
otherwise has access.&lt;/p&gt;
&lt;p&gt;The feed handlers are registered with `webAuth.AllowBasic` (so they accept token Basic auth) but call
no scope / public-only check.…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6cqf-375w-639g</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2304 — Gitea: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</guid>
    </item>
  </channel>
</rss>
