<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 13:52:17 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-352285</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352285</link>
      <description>EUVD-2026-352285</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352285</guid>
    </item>
    <item>
      <title>fkie_cve-2026-57897</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-57897</link>
      <description>&lt;p&gt;Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-57897</guid>
    </item>
    <item>
      <title>GHSA-frpw-3h2q-4jj6 — Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-frpw-3h2q-4jj6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;**Author:** Prakhar Porwal
**Date:** 2026-05-24
**Target:** Gitea (self-hosted Git service)
**Branch tested:** `main` @ `b7e95cc48c` (development build, go1.26.3)
**Component:** `routers/api/v1/org/action.go` (org-level Actions API)
**OWASP:** API3:2023 Broken Object Property Level Authorization&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## 1. Summary&lt;/p&gt;
&lt;p&gt;The org-level Actions REST endpoints&lt;/p&gt;
&lt;p&gt;```
GET /api/v1/orgs/{org}/actions/runs
GET /api/v1/orgs/{org}/actions/jobs
```&lt;/p&gt;
&lt;p&gt;are gated only by **`reqOrgMembership()`** + `reqToken()`. They then call
`shared.ListRuns(ctx, ctx.Org.Organization.ID, 0)` /
`shared.ListJobs(ctx, ctx.Org.Organization.ID, 0, 0, nil)`, which selects
**every** `action_run` / `action_run_job` row whose repository belongs to the
org — with **no per-repository ACL check**.&lt;/p&gt;
&lt;p&gt;Result: any user who is a member of an organization can enumerate workflow
runs and jobs from **every repository in that org**, including:&lt;/p&gt;
&lt;p&gt;* private repositories the caller has no team membership for,
* repositories where the caller has been explicitly denied the `repo.actions`
  unit,
* repositories created by other teams the caller is not part of.&lt;/p&gt;
&lt;p&gt;Direct per-repo equivalents (`GET /api/v1/repos/{owner}/{repo}/actions/runs`,
`…/jobs/{job_id}/logs`, `…/runs/{run_id}/jobs`) correctly return `404` for the
same caller — proving the org-level surface is the only path that leaks.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## 2. Affected Code&lt;/p&gt;
&lt;p&gt;### 2.1 Route registration&lt;/p&gt;
&lt;p&gt;`routers/api/v1/api.go:1647-1652`&lt;/p&gt;
&lt;p&gt;```go
addActionsRoutes(
    m,
    reqOrgMembership(),   // reqR…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;**Author:** Prakhar Porwal
**Date:** 2026-05-24
**Target:** Gitea (self-hosted Git service)
**Branch tested:** `main` @ `b7e95cc48c` (development build, go1.26.3)
**Component:** `routers/api/v1/org/action.go` (org-level Actions API)
**OWASP:** API3:2023 Broken Object Property Level Authorization&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## 1. Summary&lt;/p&gt;
&lt;p&gt;The org-level Actions REST endpoints&lt;/p&gt;
&lt;p&gt;```
GET /api/v1/orgs/{org}/actions/runs
GET /api/v1/orgs/{org}/actions/jobs
```&lt;/p&gt;
&lt;p&gt;are gated only by **`reqOrgMembership()`** + `reqToken()`. They then call
`shared.ListRuns(ctx, ctx.Org.Organization.ID, 0)` /
`shared.ListJobs(ctx, ctx.Org.Organization.ID, 0, 0, nil)`, which selects
**every** `action_run` / `action_run_job` row whose repository belongs to the
org — with **no per-repository ACL check**.&lt;/p&gt;
&lt;p&gt;Result: any user who is a member of an organization can enumerate workflow
runs and jobs from **every repository in that org**, including:&lt;/p&gt;
&lt;p&gt;* private repositories the caller has no team membership for,
* repositories where the caller has been explicitly denied the `repo.actions`
  unit,
* repositories created by other teams the caller is not part of.&lt;/p&gt;
&lt;p&gt;Direct per-repo equivalents (`GET /api/v1/repos/{owner}/{repo}/actions/runs`,
`…/jobs/{job_id}/logs`, `…/runs/{run_id}/jobs`) correctly return `404` for the
same caller — proving the org-level surface is the only path that leaks.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## 2. Affected Code&lt;/p&gt;
&lt;p&gt;### 2.1 Route registration&lt;/p&gt;
&lt;p&gt;`routers/api/v1/api.go:1647-1652`&lt;/p&gt;
&lt;p&gt;```go
addActionsRoutes(
    m,
    reqOrgMembership(),   // reqR…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-frpw-3h2q-4jj6</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2304 — Gitea: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</guid>
    </item>
  </channel>
</rss>
