<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 01:35:03 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-352803</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352803</link>
      <description>EUVD-2026-352803</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352803</guid>
    </item>
    <item>
      <title>fkie_cve-2026-55982</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55982</link>
      <description>&lt;p&gt;OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-55982</guid>
    </item>
    <item>
      <title>GHSA-mg4f-x9v4-6h2p — Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mg4f-x9v4-6h2p</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The OIDC userinfo endpoint (`GET /login/oauth/userinfo`) accepts Gitea API tokens as bearer credentials but does not enforce API token scopes before returning identity claims.&lt;/p&gt;
&lt;p&gt;A personal access token scoped only to `read:misc` can successfully retrieve user information from the OIDC userinfo endpoint, even though the same token is denied access to user-related REST API endpoints that enforce scope checks.&lt;/p&gt;
&lt;p&gt;As a result, identity information remains accessible through the OIDC endpoint regardless of the scopes assigned to the API token.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Gitea supports scoped personal access tokens and enforces scope checks on user-related REST API endpoints.&lt;/p&gt;
&lt;p&gt;For example, a token scoped only to `read:misc` is denied access to endpoints such as:&lt;/p&gt;
&lt;p&gt;| Endpoint | Required Scope |
|----------|----------------|
| `GET /api/v1/user` | `read:user` |
| `GET /api/v1/user/emails` | `read:user` |
| `GET /api/v1/user/orgs` | `read:organization` |&lt;/p&gt;
&lt;p&gt;Requests to these endpoints return:&lt;/p&gt;
&lt;p&gt;```http
403 Forbidden
```&lt;/p&gt;
&lt;p&gt;with a scope-related error.&lt;/p&gt;
&lt;p&gt;However, the same `read:misc` token can be supplied as a bearer credential to:&lt;/p&gt;
&lt;p&gt;```http
GET /login/oauth/userinfo
Authorization: Bearer &amp;lt;token&amp;gt;
```&lt;/p&gt;
&lt;p&gt;and receives a successful response containing identity claims.&lt;/p&gt;
&lt;p&gt;Observed claims include:&lt;/p&gt;
&lt;p&gt;- `email`
- `groups`&lt;/p&gt;
&lt;p&gt;The `groups` claim contains organization and team membership information associated with the authenticated user.&lt;/p&gt;
&lt;p&gt;This behavior indicates that the OIDC userinfo endpoint accepts API tokens…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The OIDC userinfo endpoint (`GET /login/oauth/userinfo`) accepts Gitea API tokens as bearer credentials but does not enforce API token scopes before returning identity claims.&lt;/p&gt;
&lt;p&gt;A personal access token scoped only to `read:misc` can successfully retrieve user information from the OIDC userinfo endpoint, even though the same token is denied access to user-related REST API endpoints that enforce scope checks.&lt;/p&gt;
&lt;p&gt;As a result, identity information remains accessible through the OIDC endpoint regardless of the scopes assigned to the API token.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Gitea supports scoped personal access tokens and enforces scope checks on user-related REST API endpoints.&lt;/p&gt;
&lt;p&gt;For example, a token scoped only to `read:misc` is denied access to endpoints such as:&lt;/p&gt;
&lt;p&gt;| Endpoint | Required Scope |
|----------|----------------|
| `GET /api/v1/user` | `read:user` |
| `GET /api/v1/user/emails` | `read:user` |
| `GET /api/v1/user/orgs` | `read:organization` |&lt;/p&gt;
&lt;p&gt;Requests to these endpoints return:&lt;/p&gt;
&lt;p&gt;```http
403 Forbidden
```&lt;/p&gt;
&lt;p&gt;with a scope-related error.&lt;/p&gt;
&lt;p&gt;However, the same `read:misc` token can be supplied as a bearer credential to:&lt;/p&gt;
&lt;p&gt;```http
GET /login/oauth/userinfo
Authorization: Bearer &amp;lt;token&amp;gt;
```&lt;/p&gt;
&lt;p&gt;and receives a successful response containing identity claims.&lt;/p&gt;
&lt;p&gt;Observed claims include:&lt;/p&gt;
&lt;p&gt;- `email`
- `groups`&lt;/p&gt;
&lt;p&gt;The `groups` claim contains organization and team membership information associated with the authenticated user.&lt;/p&gt;
&lt;p&gt;This behavior indicates that the OIDC userinfo endpoint accepts API tokens…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mg4f-x9v4-6h2p</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2304 — Gitea: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</guid>
    </item>
  </channel>
</rss>
