<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 09:26:07 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-352791</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352791</link>
      <description>EUVD-2026-352791</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352791</guid>
    </item>
    <item>
      <title>fkie_cve-2026-58431</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-58431</link>
      <description>&lt;p&gt;Public-only API token restriction is not enforced on team API routes&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Public-only API token restriction is not enforced on team API routes&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-58431</guid>
    </item>
    <item>
      <title>GHSA-h56g-4qw7-2mxg — Gitea: Public-only API token restriction is not enforced on team API routes</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-h56g-4qw7-2mxg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: gitea.dev&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Gitea&amp;#39;s `/api/v1/teams/{id}` API routes do not correctly enforce the `public-only` access token restriction.&lt;/p&gt;
&lt;p&gt;A `public-only` token is intended to limit API access to public repositories and public organizations. However, several team API routes continue to return private team repository metadata and private team activity feed entries when called with a `public-only` token.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The `/api/v1/teams/{teamid}` route group uses:&lt;/p&gt;
&lt;p&gt;```go
orgAssignment(false, true)
```&lt;/p&gt;
&lt;p&gt;This loads `ctx.Org.Team`, but does not load `ctx.Org.Organization`.&lt;/p&gt;
&lt;p&gt;The `checkTokenPublicOnly` middleware checks organization visibility through `ctx.Org.Organization`. When `ctx.Org.Organization` is nil, the organization visibility check silently passes.&lt;/p&gt;
&lt;p&gt;In addition, the team repository handlers return repositories without applying repository-level `public-only` filtering:&lt;/p&gt;
&lt;p&gt;```go
repo_model.GetTeamRepositories(...)
convert.ToRepo(...)
```&lt;/p&gt;
&lt;p&gt;They do not call:&lt;/p&gt;
&lt;p&gt;```go
ctx.TokenCanAccessRepo(repo)
```&lt;/p&gt;
&lt;p&gt;The team activity feed handler also sets:&lt;/p&gt;
&lt;p&gt;```go
IncludePrivate: true
```&lt;/p&gt;
&lt;p&gt;but does not apply:&lt;/p&gt;
&lt;p&gt;```go
opts.ApplyPublicOnly(ctx.PublicOnly)
```&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;Vulnerability is verified on latest gitea release (1.26.2) and nightly build.
Frist, create a `public-only` organization-scoped token for a user who is a member of a team in a private org with private repositories:&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;1075&amp;#34; height=&amp;#34;577&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/4a01d0ab-f67c-47c9-94b1-e74ddd77d7bc&amp;#34; /&amp;gt;…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: gitea.dev&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Gitea&amp;#39;s `/api/v1/teams/{id}` API routes do not correctly enforce the `public-only` access token restriction.&lt;/p&gt;
&lt;p&gt;A `public-only` token is intended to limit API access to public repositories and public organizations. However, several team API routes continue to return private team repository metadata and private team activity feed entries when called with a `public-only` token.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The `/api/v1/teams/{teamid}` route group uses:&lt;/p&gt;
&lt;p&gt;```go
orgAssignment(false, true)
```&lt;/p&gt;
&lt;p&gt;This loads `ctx.Org.Team`, but does not load `ctx.Org.Organization`.&lt;/p&gt;
&lt;p&gt;The `checkTokenPublicOnly` middleware checks organization visibility through `ctx.Org.Organization`. When `ctx.Org.Organization` is nil, the organization visibility check silently passes.&lt;/p&gt;
&lt;p&gt;In addition, the team repository handlers return repositories without applying repository-level `public-only` filtering:&lt;/p&gt;
&lt;p&gt;```go
repo_model.GetTeamRepositories(...)
convert.ToRepo(...)
```&lt;/p&gt;
&lt;p&gt;They do not call:&lt;/p&gt;
&lt;p&gt;```go
ctx.TokenCanAccessRepo(repo)
```&lt;/p&gt;
&lt;p&gt;The team activity feed handler also sets:&lt;/p&gt;
&lt;p&gt;```go
IncludePrivate: true
```&lt;/p&gt;
&lt;p&gt;but does not apply:&lt;/p&gt;
&lt;p&gt;```go
opts.ApplyPublicOnly(ctx.PublicOnly)
```&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;Vulnerability is verified on latest gitea release (1.26.2) and nightly build.
Frist, create a `public-only` organization-scoped token for a user who is a member of a team in a private org with private repositories:&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;1075&amp;#34; height=&amp;#34;577&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/4a01d0ab-f67c-47c9-94b1-e74ddd77d7bc&amp;#34; /&amp;gt;…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-h56g-4qw7-2mxg</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2304 — Gitea: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</guid>
    </item>
  </channel>
</rss>
