<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 04:53:17 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-352922</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352922</link>
      <description>EUVD-2026-352922</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352922</guid>
    </item>
    <item>
      <title>fkie_cve-2026-55987</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55987</link>
      <description>&lt;p&gt;OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-55987</guid>
    </item>
    <item>
      <title>GHSA-vrhc-jjfc-m3m3 — Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomple…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vrhc-jjfc-m3m3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;Gitea&amp;#39;s OAuth2 sign-in callback reactivates a deactivated user account (`IsActive=false`) when the user signs in through an authentication source that does not issue refresh tokens (notably GitHub, and any OIDC/OAuth2 source configured without `offline_access`). PR #38009 added a gate intended to reactivate users only when the OAuth2 auto-sync cron had disabled them, using &amp;#34;the stored refresh token is empty&amp;#34; as the signal. That signal is wrong: for sources that never issue refresh tokens, an empty refresh token is the normal state of every user, so the gate cannot distinguish a cron-disabled account from one an administrator deliberately deactivated. The next time the administrator-deactivated user signs in through the provider, Gitea sets `IsActive=true` and grants a full session, silently undoing the administrator&amp;#39;s action. This is the exact behavior #38009 was written to prevent. (`ProhibitLogin`, the hard ban, is enforced separately and is not affected.)&lt;/p&gt;
&lt;p&gt;No special privileges are required beyond being the deactivated user and being able to sign in through the source.&lt;/p&gt;
&lt;p&gt;### Root Cause&lt;/p&gt;
&lt;p&gt;`routers/web/auth/oauth.go` (the `handleOAuth2SignIn` reactivation gate):&lt;/p&gt;
&lt;p&gt;```go
if !u.IsActive {
    extLogin, hasExt, err := user_model.GetExternalLogin(ctx, authSource.ID, gothUser.UserID)
    if err != nil { ctx.ServerError(&amp;#34;GetExternalLogin&amp;#34;, err); return }
    isDisabledByAutoSync := hasExt &amp;amp;&amp;amp; extLogin.RefreshToken == &amp;#34;&amp;#34;   // wrong signal
    if isDisabledByAutoSync {…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;Gitea&amp;#39;s OAuth2 sign-in callback reactivates a deactivated user account (`IsActive=false`) when the user signs in through an authentication source that does not issue refresh tokens (notably GitHub, and any OIDC/OAuth2 source configured without `offline_access`). PR #38009 added a gate intended to reactivate users only when the OAuth2 auto-sync cron had disabled them, using &amp;#34;the stored refresh token is empty&amp;#34; as the signal. That signal is wrong: for sources that never issue refresh tokens, an empty refresh token is the normal state of every user, so the gate cannot distinguish a cron-disabled account from one an administrator deliberately deactivated. The next time the administrator-deactivated user signs in through the provider, Gitea sets `IsActive=true` and grants a full session, silently undoing the administrator&amp;#39;s action. This is the exact behavior #38009 was written to prevent. (`ProhibitLogin`, the hard ban, is enforced separately and is not affected.)&lt;/p&gt;
&lt;p&gt;No special privileges are required beyond being the deactivated user and being able to sign in through the source.&lt;/p&gt;
&lt;p&gt;### Root Cause&lt;/p&gt;
&lt;p&gt;`routers/web/auth/oauth.go` (the `handleOAuth2SignIn` reactivation gate):&lt;/p&gt;
&lt;p&gt;```go
if !u.IsActive {
    extLogin, hasExt, err := user_model.GetExternalLogin(ctx, authSource.ID, gothUser.UserID)
    if err != nil { ctx.ServerError(&amp;#34;GetExternalLogin&amp;#34;, err); return }
    isDisabledByAutoSync := hasExt &amp;amp;&amp;amp; extLogin.RefreshToken == &amp;#34;&amp;#34;   // wrong signal
    if isDisabledByAutoSync {…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vrhc-jjfc-m3m3</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2304 — Gitea: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</guid>
    </item>
  </channel>
</rss>
