<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 03:00:21 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-352804</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352804</link>
      <description>EUVD-2026-352804</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352804</guid>
    </item>
    <item>
      <title>fkie_cve-2026-58420</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-58420</link>
      <description>&lt;p&gt;Local File Inclusion via file:// URI in Migration Restore&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Local File Inclusion via file:// URI in Migration Restore&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-58420</guid>
    </item>
    <item>
      <title>GHSA-5ggr-2f2h-jmvm — Gitea: Local File Inclusion via file:// URI in Migration Restore</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5ggr-2f2h-jmvm</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: gitea.dev&lt;/p&gt;
&lt;p&gt;# Local File Inclusion via file:// URI in Migration Restore&lt;/p&gt;
&lt;p&gt;Target: go-gitea/gitea
Component: services/migrations/gitea_uploader.go, modules/uri/uri.go
Severity: High
Affected Versions: &amp;lt;= v1.22.x (all releases), master as of latest commit
Researchers:
- Isa Can — Eresus Security (https://github.com/isa0-gh)
- Yigit Ibrahim — Eresus Security (https://github.com/ibrahmsql)&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Gitea&amp;#39;s restore-repo command processes release.yml files from a user-supplied archive. The DownloadURL field in each release attachment is passed to uri.Open() without scheme validation. Because uri.Open() supports the file:// scheme via os.Open(), an operator-level attacker can plant a crafted release.yml to exfiltrate arbitrary files from the server filesystem as release attachments.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;An attacker who can supply a crafted archive to the restore-repo command can read any file accessible to the Gitea process user on the host filesystem. Sensitive targets include:&lt;/p&gt;
&lt;p&gt;- app.ini — containing database passwords and secret keys
- SSH private keys (~/.ssh/id_rsa, /etc/ssh/ssh_host_*)
- TLS certificates and private keys
- Cloud provider credential files (e.g. ~/.aws/credentials)
- Any other file readable by the Gitea process user&lt;/p&gt;
&lt;p&gt;The exfiltrated content is silently stored as a release attachment and retrievable via the Gitea API.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Affected Code&lt;/p&gt;
&lt;p&gt;### modules/uri/uri.go
```
func Open(rawURL string) (io.ReadCloser, error) {
    u, err := url.Parse(rawURL)
    if err != nil {…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: gitea.dev&lt;/p&gt;
&lt;p&gt;# Local File Inclusion via file:// URI in Migration Restore&lt;/p&gt;
&lt;p&gt;Target: go-gitea/gitea
Component: services/migrations/gitea_uploader.go, modules/uri/uri.go
Severity: High
Affected Versions: &amp;lt;= v1.22.x (all releases), master as of latest commit
Researchers:
- Isa Can — Eresus Security (https://github.com/isa0-gh)
- Yigit Ibrahim — Eresus Security (https://github.com/ibrahmsql)&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Gitea&amp;#39;s restore-repo command processes release.yml files from a user-supplied archive. The DownloadURL field in each release attachment is passed to uri.Open() without scheme validation. Because uri.Open() supports the file:// scheme via os.Open(), an operator-level attacker can plant a crafted release.yml to exfiltrate arbitrary files from the server filesystem as release attachments.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;An attacker who can supply a crafted archive to the restore-repo command can read any file accessible to the Gitea process user on the host filesystem. Sensitive targets include:&lt;/p&gt;
&lt;p&gt;- app.ini — containing database passwords and secret keys
- SSH private keys (~/.ssh/id_rsa, /etc/ssh/ssh_host_*)
- TLS certificates and private keys
- Cloud provider credential files (e.g. ~/.aws/credentials)
- Any other file readable by the Gitea process user&lt;/p&gt;
&lt;p&gt;The exfiltrated content is silently stored as a release attachment and retrievable via the Gitea API.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Affected Code&lt;/p&gt;
&lt;p&gt;### modules/uri/uri.go
```
func Open(rawURL string) (io.ReadCloser, error) {
    u, err := url.Parse(rawURL)
    if err != nil {…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5ggr-2f2h-jmvm</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2304 — Gitea: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</guid>
    </item>
  </channel>
</rss>
