<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 16:34:42 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-333340</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-333340</link>
      <description>EUVD-2026-333340</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-333340</guid>
    </item>
    <item>
      <title>fkie_cve-2026-58423</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-58423</link>
      <description>&lt;p&gt;LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-58423</guid>
    </item>
    <item>
      <title>GHSA-7wvc-rvp7-w99x — Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7wvc-rvp7-w99x</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A flaw in SSH LFS sub-verb handling allows any authenticated SSH user to obtain valid LFS credentials for any repository on the instance, including private repositories they have no access to. This enables unauthorized download of all LFS objects from any private repository.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;In `cmd/serv.go`, the `getAccessMode` function determines the required access level for SSH operations. For LFS verbs (`git-lfs-authenticate`, `git-lfs-transfer`), it switches on the sub-verb (`upload`/`download`). If the sub-verb is neither, execution falls through to:&lt;/p&gt;
&lt;p&gt;```go
setting.PanicInDevOrTesting(&amp;#34;unknown verb: %s %s&amp;#34;, verb, lfsVerb)
return perm.AccessModeNone
```&lt;/p&gt;
&lt;p&gt;In production (`IsProd=true`), `PanicInDevOrTesting` only logs an error and does not panic. `AccessModeNone` (value `0`) is then passed to `ServCommand` in `routers/private/serv.go`, where the permission check block at line ~322 evaluates:&lt;/p&gt;
&lt;p&gt;```go
if repoExist &amp;amp;&amp;amp;
    (mode &amp;gt; perm.AccessModeRead ||
     repo.IsPrivate ||
     owner.Visibility.IsPrivate() ||
     (user != nil &amp;amp;&amp;amp; user.IsRestricted) ||
     setting.Service.RequireSignInViewStrict) {
    ...
    if userMode &amp;lt; mode {  // userMode &amp;lt; 0 is always false
        // deny access
    }
}
```&lt;/p&gt;
&lt;p&gt;For private repositories, `repo.IsPrivate` triggers the permission check block, but `userMode &amp;lt; mode` evaluates to `userMode &amp;lt; 0`, which is always false — **access is granted regardless of the user&amp;#39;s actual permissions**.&lt;/p&gt;
&lt;p&gt;The function then returns successfully, and `r…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A flaw in SSH LFS sub-verb handling allows any authenticated SSH user to obtain valid LFS credentials for any repository on the instance, including private repositories they have no access to. This enables unauthorized download of all LFS objects from any private repository.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;In `cmd/serv.go`, the `getAccessMode` function determines the required access level for SSH operations. For LFS verbs (`git-lfs-authenticate`, `git-lfs-transfer`), it switches on the sub-verb (`upload`/`download`). If the sub-verb is neither, execution falls through to:&lt;/p&gt;
&lt;p&gt;```go
setting.PanicInDevOrTesting(&amp;#34;unknown verb: %s %s&amp;#34;, verb, lfsVerb)
return perm.AccessModeNone
```&lt;/p&gt;
&lt;p&gt;In production (`IsProd=true`), `PanicInDevOrTesting` only logs an error and does not panic. `AccessModeNone` (value `0`) is then passed to `ServCommand` in `routers/private/serv.go`, where the permission check block at line ~322 evaluates:&lt;/p&gt;
&lt;p&gt;```go
if repoExist &amp;amp;&amp;amp;
    (mode &amp;gt; perm.AccessModeRead ||
     repo.IsPrivate ||
     owner.Visibility.IsPrivate() ||
     (user != nil &amp;amp;&amp;amp; user.IsRestricted) ||
     setting.Service.RequireSignInViewStrict) {
    ...
    if userMode &amp;lt; mode {  // userMode &amp;lt; 0 is always false
        // deny access
    }
}
```&lt;/p&gt;
&lt;p&gt;For private repositories, `repo.IsPrivate` triggers the permission check block, but `userMode &amp;lt; mode` evaluates to `userMode &amp;lt; 0`, which is always false — **access is granted regardless of the user&amp;#39;s actual permissions**.&lt;/p&gt;
&lt;p&gt;The function then returns successfully, and `r…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7wvc-rvp7-w99x</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2149 — Gitea: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2149</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um seine Privilegien zu erhöhen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um seine Privilegien zu erhöhen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2149</guid>
    </item>
  </channel>
</rss>
