<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 02:01:38 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-352282</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352282</link>
      <description>EUVD-2026-352282</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352282</guid>
    </item>
    <item>
      <title>fkie_cve-2026-58416</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-58416</link>
      <description>&lt;p&gt;Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-58416</guid>
    </item>
    <item>
      <title>GHSA-fj8v-hjwv-qm88 — Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR gua…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fj8v-hjwv-qm88</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: gitea.dev&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`GetActionsUserRepoPermission` (`models/perm/access/repo_permission.go`) decides whether an Actions
task token may access a target repo. Its cross-repo branches each enforce a fork-PR discriminator —
**except the collaborative-owner branch**, which is missing the `!task.IsForkPullRequest` guard that
its sibling has. As a result, when a private repo **B** lists owner **A** as a collaborative owner, an
**attacker-controlled fork pull-request** workflow whose base repo is owned by A is granted code-read
on B — i.e. the fork&amp;#39;s YAML can clone a third private repository it has no rights to.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;```go
// models/perm/access/repo_permission.go (v1.26.2), in GetActionsUserRepoPermission
if checkSameOwnerCrossRepoAccess(ctx, taskRepo, repo, task.IsForkPullRequest) { // passes isForkPR -&amp;gt; denies forks
    return maxPerm, nil
}
...
if taskRepo.IsPrivate {                                   // &amp;lt;-- NO IsForkPullRequest check here
    actionsUnit := repo.MustGetUnit(ctx, unit.TypeActions)
    if actionsUnit.ActionsConfig().IsCollaborativeOwner(taskRepo.OwnerID) {
        return maxPerm, nil                              // grants code-read to target repo B
    }
}
```&lt;/p&gt;
&lt;p&gt;The sibling same-owner path correctly denies fork PRs:&lt;/p&gt;
&lt;p&gt;```go
func checkSameOwnerCrossRepoAccess(ctx, taskRepo, targetRepo, isForkPR bool) bool {
    if isForkPR {
        return false // Fork PRs are never allowed cross-repo access to other private repositories.
    }
    ...
}
```&lt;/p&gt;
&lt;p&gt;`taskRepo` = the repo…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: gitea.dev&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`GetActionsUserRepoPermission` (`models/perm/access/repo_permission.go`) decides whether an Actions
task token may access a target repo. Its cross-repo branches each enforce a fork-PR discriminator —
**except the collaborative-owner branch**, which is missing the `!task.IsForkPullRequest` guard that
its sibling has. As a result, when a private repo **B** lists owner **A** as a collaborative owner, an
**attacker-controlled fork pull-request** workflow whose base repo is owned by A is granted code-read
on B — i.e. the fork&amp;#39;s YAML can clone a third private repository it has no rights to.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;```go
// models/perm/access/repo_permission.go (v1.26.2), in GetActionsUserRepoPermission
if checkSameOwnerCrossRepoAccess(ctx, taskRepo, repo, task.IsForkPullRequest) { // passes isForkPR -&amp;gt; denies forks
    return maxPerm, nil
}
...
if taskRepo.IsPrivate {                                   // &amp;lt;-- NO IsForkPullRequest check here
    actionsUnit := repo.MustGetUnit(ctx, unit.TypeActions)
    if actionsUnit.ActionsConfig().IsCollaborativeOwner(taskRepo.OwnerID) {
        return maxPerm, nil                              // grants code-read to target repo B
    }
}
```&lt;/p&gt;
&lt;p&gt;The sibling same-owner path correctly denies fork PRs:&lt;/p&gt;
&lt;p&gt;```go
func checkSameOwnerCrossRepoAccess(ctx, taskRepo, targetRepo, isForkPR bool) bool {
    if isForkPR {
        return false // Fork PRs are never allowed cross-repo access to other private repositories.
    }
    ...
}
```&lt;/p&gt;
&lt;p&gt;`taskRepo` = the repo…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fj8v-hjwv-qm88</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2304 — Gitea: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</guid>
    </item>
  </channel>
</rss>
