<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 00:54:55 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-352802</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352802</link>
      <description>EUVD-2026-352802</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352802</guid>
    </item>
    <item>
      <title>fkie_cve-2026-55984</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55984</link>
      <description>&lt;p&gt;Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-55984</guid>
    </item>
    <item>
      <title>GHSA-m932-crvm-gcp5 — Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m932-crvm-gcp5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The AddTime API handler continues execution after an error returned by `GetUserByName()`.&lt;/p&gt;
&lt;p&gt;When a repository administrator specifies a non-existent user name, an error response is generated but execution does not stop. Subsequent code dereferences a nil user pointer, resulting in a runtime panic.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Affected endpoint:&lt;/p&gt;
&lt;p&gt;```http
POST /api/v1/repos/{owner}/{repo}/issues/{index}/times
```&lt;/p&gt;
&lt;p&gt;Affected file:&lt;/p&gt;
&lt;p&gt;```text
routers/api/v1/repo/issue_tracked_time.go
```&lt;/p&gt;
&lt;p&gt;Relevant code:&lt;/p&gt;
&lt;p&gt;```go
user, err = user_model.GetUserByName(ctx, form.User)
if err != nil {
    ctx.APIErrorInternal(err)
    // missing return
}
```&lt;/p&gt;
&lt;p&gt;Execution continues to:&lt;/p&gt;
&lt;p&gt;```go
trackedTime, err := issues_model.AddTime(
    ctx,
    user,
    issue,
    form.Time,
    created,
)
```&lt;/p&gt;
&lt;p&gt;When `GetUserByName()` fails, `user` is nil.&lt;/p&gt;
&lt;p&gt;The subsequent call dereferences the nil pointer and triggers a runtime panic.&lt;/p&gt;
&lt;p&gt;### Proof of Concept&lt;/p&gt;
&lt;p&gt;Using a repository administrator account:&lt;/p&gt;
&lt;p&gt;```http
POST /api/v1/repos/owner/repo/issues/1/times
Content-Type: application/json&lt;/p&gt;
&lt;p&gt;{
  &amp;#34;time&amp;#34;: 3600,
  &amp;#34;user_name&amp;#34;: &amp;#34;nonexistent_user_xyz&amp;#34;
}
```&lt;/p&gt;
&lt;p&gt;Result:&lt;/p&gt;
&lt;p&gt;```text
HTTP 500
runtime error: invalid memory address or nil pointer dereference
```&lt;/p&gt;
&lt;p&gt;The stack trace indicates execution reaches the AddTime code path with a nil user object.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;An authenticated repository administrator can repeatedly trigger server-side panics through the affected endpoint.&lt;/p&gt;
&lt;p&gt;Depending on deployment configuration and panic recovery behavior, this m…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The AddTime API handler continues execution after an error returned by `GetUserByName()`.&lt;/p&gt;
&lt;p&gt;When a repository administrator specifies a non-existent user name, an error response is generated but execution does not stop. Subsequent code dereferences a nil user pointer, resulting in a runtime panic.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Affected endpoint:&lt;/p&gt;
&lt;p&gt;```http
POST /api/v1/repos/{owner}/{repo}/issues/{index}/times
```&lt;/p&gt;
&lt;p&gt;Affected file:&lt;/p&gt;
&lt;p&gt;```text
routers/api/v1/repo/issue_tracked_time.go
```&lt;/p&gt;
&lt;p&gt;Relevant code:&lt;/p&gt;
&lt;p&gt;```go
user, err = user_model.GetUserByName(ctx, form.User)
if err != nil {
    ctx.APIErrorInternal(err)
    // missing return
}
```&lt;/p&gt;
&lt;p&gt;Execution continues to:&lt;/p&gt;
&lt;p&gt;```go
trackedTime, err := issues_model.AddTime(
    ctx,
    user,
    issue,
    form.Time,
    created,
)
```&lt;/p&gt;
&lt;p&gt;When `GetUserByName()` fails, `user` is nil.&lt;/p&gt;
&lt;p&gt;The subsequent call dereferences the nil pointer and triggers a runtime panic.&lt;/p&gt;
&lt;p&gt;### Proof of Concept&lt;/p&gt;
&lt;p&gt;Using a repository administrator account:&lt;/p&gt;
&lt;p&gt;```http
POST /api/v1/repos/owner/repo/issues/1/times
Content-Type: application/json&lt;/p&gt;
&lt;p&gt;{
  &amp;#34;time&amp;#34;: 3600,
  &amp;#34;user_name&amp;#34;: &amp;#34;nonexistent_user_xyz&amp;#34;
}
```&lt;/p&gt;
&lt;p&gt;Result:&lt;/p&gt;
&lt;p&gt;```text
HTTP 500
runtime error: invalid memory address or nil pointer dereference
```&lt;/p&gt;
&lt;p&gt;The stack trace indicates execution reaches the AddTime code path with a nil user object.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;An authenticated repository administrator can repeatedly trigger server-side panics through the affected endpoint.&lt;/p&gt;
&lt;p&gt;Depending on deployment configuration and panic recovery behavior, this m…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m932-crvm-gcp5</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2304 — Gitea: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</guid>
    </item>
  </channel>
</rss>
