<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 09:20:08 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-352921</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352921</link>
      <description>EUVD-2026-352921</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352921</guid>
    </item>
    <item>
      <title>fkie_cve-2026-56443</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-56443</link>
      <description>&lt;p&gt;Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-56443</guid>
    </item>
    <item>
      <title>GHSA-7p4h-3gxq-x3h3 — Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7p4h-3gxq-x3h3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea, Go: gitea.dev&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;After [PR #37118](https://github.com/go-gitea/gitea/pull/37118) / **CVE-2026-25714**
(`fix: Unify public-only token filtering in API queries and repo access checks`,
merged 2026-05-18, backport `#37773` to 1.26.2 — the May 2026 unification pass
for public-only token filtering, reporter Medoedus per the 1.26.2 release notes),
the `public-only` PAT scope is still bypassable on **Repository** and **Package**
scope categories when the owner&amp;#39;s `Visibility = Limited` (instance-internal).&lt;/p&gt;
&lt;p&gt;The sibling `Org` / `User` / `ActivityPub` cases in the same `checkTokenPublicOnly`
switch correctly reject Limited owners via `!Visibility.IsPublic()`. The
Repository / Package cases use `repo.IsPrivate` or `Owner.Visibility.IsPrivate()`,
both of which return `false` for `VisibleTypeLimited` — so a `public-only` PAT
strictly exceeds anonymous reach on a Limited owner.&lt;/p&gt;
&lt;p&gt;Tested on `gitea/gitea:1.26.2`. The decisive marker is that PR #37118&amp;#39;s
unification IS applied in the version under test (User-category PROBE returns
`403 &amp;#34;token scope is limited to public users&amp;#34;`). Despite that, the
Repository-category PROBE on the same Limited owner with the same PAT returns
`200` and serves content.&lt;/p&gt;
&lt;p&gt;## Affected entry points (4 spots)&lt;/p&gt;
&lt;p&gt;| File:Line | Function | Affected surface |
|---|---|---|
| `routers/api/v1/api.go:292` | `checkTokenPublicOnly` Package case | API v1 packages |
| `routers/api/packages/api.go:76` | `reqPackageAccess` middleware | All 24 native package registries (`/api/packages/&amp;lt;typ…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea, Go: gitea.dev&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;After [PR #37118](https://github.com/go-gitea/gitea/pull/37118) / **CVE-2026-25714**
(`fix: Unify public-only token filtering in API queries and repo access checks`,
merged 2026-05-18, backport `#37773` to 1.26.2 — the May 2026 unification pass
for public-only token filtering, reporter Medoedus per the 1.26.2 release notes),
the `public-only` PAT scope is still bypassable on **Repository** and **Package**
scope categories when the owner&amp;#39;s `Visibility = Limited` (instance-internal).&lt;/p&gt;
&lt;p&gt;The sibling `Org` / `User` / `ActivityPub` cases in the same `checkTokenPublicOnly`
switch correctly reject Limited owners via `!Visibility.IsPublic()`. The
Repository / Package cases use `repo.IsPrivate` or `Owner.Visibility.IsPrivate()`,
both of which return `false` for `VisibleTypeLimited` — so a `public-only` PAT
strictly exceeds anonymous reach on a Limited owner.&lt;/p&gt;
&lt;p&gt;Tested on `gitea/gitea:1.26.2`. The decisive marker is that PR #37118&amp;#39;s
unification IS applied in the version under test (User-category PROBE returns
`403 &amp;#34;token scope is limited to public users&amp;#34;`). Despite that, the
Repository-category PROBE on the same Limited owner with the same PAT returns
`200` and serves content.&lt;/p&gt;
&lt;p&gt;## Affected entry points (4 spots)&lt;/p&gt;
&lt;p&gt;| File:Line | Function | Affected surface |
|---|---|---|
| `routers/api/v1/api.go:292` | `checkTokenPublicOnly` Package case | API v1 packages |
| `routers/api/packages/api.go:76` | `reqPackageAccess` middleware | All 24 native package registries (`/api/packages/&amp;lt;typ…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7p4h-3gxq-x3h3</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2304 — Gitea: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</guid>
    </item>
  </channel>
</rss>
