<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 06:05:39 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-330206</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-330206</link>
      <description>EUVD-2026-330206</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-330206</guid>
    </item>
    <item>
      <title>fkie_cve-2026-52801</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-52801</link>
      <description>&lt;p&gt;Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Gogs Mirror Settings functionality provide an alternative way from the well protected New Migration functionality for any authenticated users to import local repositories. This issue stems from a lack of validation of SaveAddress function. This vulnerability is fixed in 0.14.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Gogs Mirror Settings functionality provide an alternative way from the well protected New Migration functionality for any authenticated users to import local repositories. This issue stems from a lack of validation of SaveAddress function. This vulnerability is fixed in 0.14.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-52801</guid>
    </item>
    <item>
      <title>GHSA-wv27-2vqp-j7g5 — Gogs has the ability to import local repositories via Mirror Settings</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wv27-2vqp-j7g5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: gogs.io/gogs&lt;/p&gt;
&lt;p&gt;### Summary
The Gogs Mirror Settings functionality provide an alternative way from the well protected New Migration functionality for any authenticated users to import local repositories. This issue stems from a lack of validation of SaveAddress function.&lt;/p&gt;
&lt;p&gt;### Details
Here is the function implementation of the secure New Migration functionality.
&amp;lt;img width=&amp;#34;1200&amp;#34; height=&amp;#34;755&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/a6c2f307-715e-4451-bbc1-7bd934d56f96&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;Here is the function implementation of the Mirror Settings without any validation.
&amp;lt;img width=&amp;#34;1200&amp;#34; height=&amp;#34;477&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/a11c41b8-1d08-499c-bce6-ab40844211d7&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;### PoC
The New Migration feature correctly blocked my attempt to import a local repository.
&amp;lt;img width=&amp;#34;1200&amp;#34; height=&amp;#34;1008&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/dfc5aa3f-1cc4-427d-b7fe-274363c83c4e&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;But if I create a normal migration with a valid repository.
&amp;lt;img width=&amp;#34;1200&amp;#34; height=&amp;#34;1006&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/c96b356e-8ca9-4e79-a69b-ff14593c0cac&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;Then, I could use the Mirror Settings feature under the Repository Settings sync a local repository.
&amp;lt;img width=&amp;#34;1200&amp;#34; height=&amp;#34;476&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/9105475c-ae68-4d93-96d5-a3ec356deba7&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;Here is the result after the sync.
&amp;lt;img width=&amp;#34;1200&amp;#34; height=&amp;#34;533&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/1df76642-3e55-4493-a4…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: gogs.io/gogs&lt;/p&gt;
&lt;p&gt;### Summary
The Gogs Mirror Settings functionality provide an alternative way from the well protected New Migration functionality for any authenticated users to import local repositories. This issue stems from a lack of validation of SaveAddress function.&lt;/p&gt;
&lt;p&gt;### Details
Here is the function implementation of the secure New Migration functionality.
&amp;lt;img width=&amp;#34;1200&amp;#34; height=&amp;#34;755&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/a6c2f307-715e-4451-bbc1-7bd934d56f96&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;Here is the function implementation of the Mirror Settings without any validation.
&amp;lt;img width=&amp;#34;1200&amp;#34; height=&amp;#34;477&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/a11c41b8-1d08-499c-bce6-ab40844211d7&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;### PoC
The New Migration feature correctly blocked my attempt to import a local repository.
&amp;lt;img width=&amp;#34;1200&amp;#34; height=&amp;#34;1008&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/dfc5aa3f-1cc4-427d-b7fe-274363c83c4e&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;But if I create a normal migration with a valid repository.
&amp;lt;img width=&amp;#34;1200&amp;#34; height=&amp;#34;1006&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/c96b356e-8ca9-4e79-a69b-ff14593c0cac&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;Then, I could use the Mirror Settings feature under the Repository Settings sync a local repository.
&amp;lt;img width=&amp;#34;1200&amp;#34; height=&amp;#34;476&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/9105475c-ae68-4d93-96d5-a3ec356deba7&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;Here is the result after the sync.
&amp;lt;img width=&amp;#34;1200&amp;#34; height=&amp;#34;533&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/1df76642-3e55-4493-a4…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wv27-2vqp-j7g5</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2013 — Gogs: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2013</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gogs ausnutzen, um erweiterte Berechtigungen zu erlangen, beliebigen Code auszuführen – sogar mit erweiterten Berechtigungen, was zur vollständigen Kontrolle über das System führen kann –, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, Cross-Site-Scripting-Angriffe durchzuführen, Benutzer auf bösartige Websites umzuleiten oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gogs ausnutzen, um erweiterte Berechtigungen zu erlangen, beliebigen Code auszuführen – sogar mit erweiterten Berechtigungen, was zur vollständigen Kontrolle über das System führen kann –, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, Cross-Site-Scripting-Angriffe durchzuführen, Benutzer auf bösartige Websites umzuleiten oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2013</guid>
    </item>
  </channel>
</rss>
