<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 10:08:57 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-330191</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-330191</link>
      <description>EUVD-2026-330191</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-330191</guid>
    </item>
    <item>
      <title>fkie_cve-2026-52799</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-52799</link>
      <description>&lt;p&gt;Gogs is an open source self-hosted Git service. Prior to 0.14.3, GET /attachments/:uuid returns the raw attachment file without verifying whether the requester has view permission for the associated Issue/Comment/Release or the repository.
In a test environment with REQUIRE_SIGNIN_VIEW = false, we confirmed that an unauthenticated user can download attachments belonging to a private repository. This vulnerability is fixed in 0.14.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Gogs is an open source self-hosted Git service. Prior to 0.14.3, GET /attachments/:uuid returns the raw attachment file without verifying whether the requester has view permission for the associated Issue/Comment/Release or the repository.
In a test environment with REQUIRE_SIGNIN_VIEW = false, we confirmed that an unauthenticated user can download attachments belonging to a private repository. This vulnerability is fixed in 0.14.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-52799</guid>
    </item>
    <item>
      <title>GHSA-p9f5-h3rx-j5qw — Gogs Missing Authorization in Attachment Download</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-p9f5-h3rx-j5qw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: gogs.io/gogs&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;In Gogs 0.14.1, `GET /attachments/:uuid` returns the raw attachment file **without verifying whether the requester has view permission for the associated Issue/Comment/Release or the repository**.
In a test environment with `REQUIRE_SIGNIN_VIEW = false`, we confirmed that **an unauthenticated user can download attachments belonging to a private repository**.&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;`/attachments/:uuid` retrieves an attachment record solely by the UUID provided in the URL and returns the corresponding local file **without performing any authorization checks** against the attachment’s parent object (Issue/Comment/Release) or the repository it belongs to. As a result, even attachments under private repositories can be downloaded by an unauthenticated user (or a user without proper permissions) as long as the UUID is known.&lt;/p&gt;
&lt;p&gt;Relevant code (internal/cmd/web.go:306):&lt;/p&gt;
&lt;p&gt;```go
m.Get(&amp;#34;/attachments/:uuid&amp;#34;, func(c *context.Context) {
	attach, err := database.GetAttachmentByUUID(c.Params(&amp;#34;:uuid&amp;#34;))
	if err != nil {
		c.NotFoundOrError(err, &amp;#34;get attachment by UUID&amp;#34;)
		return
	} else if !com.IsFile(attach.LocalPath()) {
		c.NotFound()
		return
	}&lt;/p&gt;
&lt;p&gt;fr, err := os.Open(attach.LocalPath())
	if err != nil {
		c.Error(err, &amp;#34;open attachment file&amp;#34;)
		return
	}
	defer fr.Close()&lt;/p&gt;
&lt;p&gt;c.Header().Set(&amp;#34;Content-Security-Policy&amp;#34;, &amp;#34;default-src &amp;#39;none&amp;#39;; style-src &amp;#39;unsafe-inline&amp;#39;; sandbox&amp;#34;)
	c.Header().Set(&amp;#34;Cache-Control&amp;#34;, &amp;#34;public,max-age=86400&amp;#34;)
	c.Header().Set(&amp;#34;Content-Disposition&amp;#34;, fmt.Sprintf(`inline;…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: gogs.io/gogs&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;In Gogs 0.14.1, `GET /attachments/:uuid` returns the raw attachment file **without verifying whether the requester has view permission for the associated Issue/Comment/Release or the repository**.
In a test environment with `REQUIRE_SIGNIN_VIEW = false`, we confirmed that **an unauthenticated user can download attachments belonging to a private repository**.&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;`/attachments/:uuid` retrieves an attachment record solely by the UUID provided in the URL and returns the corresponding local file **without performing any authorization checks** against the attachment’s parent object (Issue/Comment/Release) or the repository it belongs to. As a result, even attachments under private repositories can be downloaded by an unauthenticated user (or a user without proper permissions) as long as the UUID is known.&lt;/p&gt;
&lt;p&gt;Relevant code (internal/cmd/web.go:306):&lt;/p&gt;
&lt;p&gt;```go
m.Get(&amp;#34;/attachments/:uuid&amp;#34;, func(c *context.Context) {
	attach, err := database.GetAttachmentByUUID(c.Params(&amp;#34;:uuid&amp;#34;))
	if err != nil {
		c.NotFoundOrError(err, &amp;#34;get attachment by UUID&amp;#34;)
		return
	} else if !com.IsFile(attach.LocalPath()) {
		c.NotFound()
		return
	}&lt;/p&gt;
&lt;p&gt;fr, err := os.Open(attach.LocalPath())
	if err != nil {
		c.Error(err, &amp;#34;open attachment file&amp;#34;)
		return
	}
	defer fr.Close()&lt;/p&gt;
&lt;p&gt;c.Header().Set(&amp;#34;Content-Security-Policy&amp;#34;, &amp;#34;default-src &amp;#39;none&amp;#39;; style-src &amp;#39;unsafe-inline&amp;#39;; sandbox&amp;#34;)
	c.Header().Set(&amp;#34;Cache-Control&amp;#34;, &amp;#34;public,max-age=86400&amp;#34;)
	c.Header().Set(&amp;#34;Content-Disposition&amp;#34;, fmt.Sprintf(`inline;…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-p9f5-h3rx-j5qw</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2013 — Gogs: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2013</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gogs ausnutzen, um erweiterte Berechtigungen zu erlangen, beliebigen Code auszuführen – sogar mit erweiterten Berechtigungen, was zur vollständigen Kontrolle über das System führen kann –, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, Cross-Site-Scripting-Angriffe durchzuführen, Benutzer auf bösartige Websites umzuleiten oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gogs ausnutzen, um erweiterte Berechtigungen zu erlangen, beliebigen Code auszuführen – sogar mit erweiterten Berechtigungen, was zur vollständigen Kontrolle über das System führen kann –, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, Cross-Site-Scripting-Angriffe durchzuführen, Benutzer auf bösartige Websites umzuleiten oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2013</guid>
    </item>
  </channel>
</rss>
