<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 00:55:49 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-352796</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352796</link>
      <description>EUVD-2026-352796</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352796</guid>
    </item>
    <item>
      <title>fkie_cve-2026-58425</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-58425</link>
      <description>&lt;p&gt;OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-58425</guid>
    </item>
    <item>
      <title>GHSA-vxv2-8j6r-pcpg — Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vxv2-8j6r-pcpg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;## Live reproduction against Gitea 1.26.1&lt;/p&gt;
&lt;p&gt;Setup: Gitea 1.26.1 docker stack with two users (`admin` and `victim`) and two OAuth applications owned by different users:&lt;/p&gt;
&lt;p&gt;```
Client A: id=5dda747d-7fdd-4694-85ff-ce4f893ce51e   owner=admin
Client B: id=588f778f-4a41-4914-ae01-85d776c369db   owner=victim
```&lt;/p&gt;
&lt;p&gt;`admin` runs an OAuth flow against Client A and obtains an access token. `victim` (acting through Client B&amp;#39;s credentials) calls the introspection endpoint with Client A&amp;#39;s access token in the body:&lt;/p&gt;
&lt;p&gt;```
$ curl -s -u &amp;#34;$B_ID:$B_SEC&amp;#34; -X POST http://localhost:3001/login/oauth/introspect \
       --data-urlencode &amp;#34;token=$CLIENT_A_ACCESS_TOKEN&amp;#34;
{
    &amp;#34;active&amp;#34;: true,
    &amp;#34;username&amp;#34;: &amp;#34;admin&amp;#34;,
    &amp;#34;iss&amp;#34;: &amp;#34;http://localhost:3001&amp;#34;,
    &amp;#34;sub&amp;#34;: &amp;#34;1&amp;#34;,
    &amp;#34;aud&amp;#34;: [
        &amp;#34;5dda747d-7fdd-4694-85ff-ce4f893ce51e&amp;#34;
    ]
}
```&lt;/p&gt;
&lt;p&gt;Note the `aud` claim: the server explicitly states the token&amp;#39;s audience is Client A, yet returns the full metadata to Client B. Per RFC 7662 section 4 (&amp;#34;The authorization server SHOULD also limit the information it discloses about each token to the resources that are authorized to receive it&amp;#34;) the introspection result must not be disclosed to clients other than the token&amp;#39;s audience.&lt;/p&gt;
&lt;p&gt;Full reproduction script attached as `poc.sh`. Full session log attached as `live_run.log`.&lt;/p&gt;
&lt;p&gt;## Root cause&lt;/p&gt;
&lt;p&gt;`routers/web/auth/oauth2_provider.go:130-175` `IntrospectOAuth`:&lt;/p&gt;
&lt;p&gt;```go
func IntrospectOAuth(ctx *context.Context) {
    clientIDValid := false
    authHeader := ctx.Req.Header.Get(&amp;#34;Auth…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;## Live reproduction against Gitea 1.26.1&lt;/p&gt;
&lt;p&gt;Setup: Gitea 1.26.1 docker stack with two users (`admin` and `victim`) and two OAuth applications owned by different users:&lt;/p&gt;
&lt;p&gt;```
Client A: id=5dda747d-7fdd-4694-85ff-ce4f893ce51e   owner=admin
Client B: id=588f778f-4a41-4914-ae01-85d776c369db   owner=victim
```&lt;/p&gt;
&lt;p&gt;`admin` runs an OAuth flow against Client A and obtains an access token. `victim` (acting through Client B&amp;#39;s credentials) calls the introspection endpoint with Client A&amp;#39;s access token in the body:&lt;/p&gt;
&lt;p&gt;```
$ curl -s -u &amp;#34;$B_ID:$B_SEC&amp;#34; -X POST http://localhost:3001/login/oauth/introspect \
       --data-urlencode &amp;#34;token=$CLIENT_A_ACCESS_TOKEN&amp;#34;
{
    &amp;#34;active&amp;#34;: true,
    &amp;#34;username&amp;#34;: &amp;#34;admin&amp;#34;,
    &amp;#34;iss&amp;#34;: &amp;#34;http://localhost:3001&amp;#34;,
    &amp;#34;sub&amp;#34;: &amp;#34;1&amp;#34;,
    &amp;#34;aud&amp;#34;: [
        &amp;#34;5dda747d-7fdd-4694-85ff-ce4f893ce51e&amp;#34;
    ]
}
```&lt;/p&gt;
&lt;p&gt;Note the `aud` claim: the server explicitly states the token&amp;#39;s audience is Client A, yet returns the full metadata to Client B. Per RFC 7662 section 4 (&amp;#34;The authorization server SHOULD also limit the information it discloses about each token to the resources that are authorized to receive it&amp;#34;) the introspection result must not be disclosed to clients other than the token&amp;#39;s audience.&lt;/p&gt;
&lt;p&gt;Full reproduction script attached as `poc.sh`. Full session log attached as `live_run.log`.&lt;/p&gt;
&lt;p&gt;## Root cause&lt;/p&gt;
&lt;p&gt;`routers/web/auth/oauth2_provider.go:130-175` `IntrospectOAuth`:&lt;/p&gt;
&lt;p&gt;```go
func IntrospectOAuth(ctx *context.Context) {
    clientIDValid := false
    authHeader := ctx.Req.Header.Get(&amp;#34;Auth…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vxv2-8j6r-pcpg</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2304 — Gitea: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</guid>
    </item>
  </channel>
</rss>
