<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 19:45:25 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-15369</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-15369</link>
      <description>bdu:2026-15369</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-15369</guid>
    </item>
    <item>
      <title>EUVD-2026-352919</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352919</link>
      <description>EUVD-2026-352919</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352919</guid>
    </item>
    <item>
      <title>fkie_cve-2026-58438</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-58438</link>
      <description>&lt;p&gt;Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-58438</guid>
    </item>
    <item>
      <title>GHSA-xv9x-fj9g-vj6h — Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xv9x-fj9g-vj6h</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: gitea.dev&lt;/p&gt;
&lt;p&gt;### Details
`RemoveDependency` in `routers/web/repo/issue_dependency.go` takes a `removeDependencyID` form parameter identifying the other issue by its global numeric ID, and fetches it with `issues_model.GetIssueByID(ctx, depID)` - no repository or permission check at all. It then calls `issues_model.RemoveIssueDependency(ctx, ctx.Doer, issue, dep, depType)` (`models/issues/dependency.go`), which deletes the dependency join row and then writes a comment referencing the removal, attributed to the calling user, onto the dependency record.&lt;/p&gt;
&lt;p&gt;The sibling function in the very same file, `AddDependency`, does this correctly when the two issues are in different repos (which `ALLOW_CROSS_REPOSITORY_DEPENDENCIES`, on by default, permits):&lt;/p&gt;
&lt;p&gt;```go
if issue.RepoID != dep.RepoID {
  if !setting.Service.AllowCrossRepositoryDependencies { ... }
  depRepoPerm, err := access_model.GetDoerRepoPermission(ctx, dep.Repo, ctx.Doer)
  if !depRepoPerm.CanReadIssuesOrPulls(dep.IsPull) {
    return // you can&amp;#39;t see this dependency
  }
}
```&lt;/p&gt;
&lt;p&gt;`RemoveDependency` has no equivalent block at all - it goes straight from resolving `dep` by ID to deleting the link, regardless of which repo `dep` lives in or whether the caller can see it. I confirmed this same code is present in the current latest release, v1.26.4.&lt;/p&gt;
&lt;p&gt;### PoC
Prerequisites: an account with write access to issues on some repo `ownerA/repoA`, and the global numeric issue ID of an issue in a private repo `repoB` that is (or was) legitimately depen…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: gitea.dev&lt;/p&gt;
&lt;p&gt;### Details
`RemoveDependency` in `routers/web/repo/issue_dependency.go` takes a `removeDependencyID` form parameter identifying the other issue by its global numeric ID, and fetches it with `issues_model.GetIssueByID(ctx, depID)` - no repository or permission check at all. It then calls `issues_model.RemoveIssueDependency(ctx, ctx.Doer, issue, dep, depType)` (`models/issues/dependency.go`), which deletes the dependency join row and then writes a comment referencing the removal, attributed to the calling user, onto the dependency record.&lt;/p&gt;
&lt;p&gt;The sibling function in the very same file, `AddDependency`, does this correctly when the two issues are in different repos (which `ALLOW_CROSS_REPOSITORY_DEPENDENCIES`, on by default, permits):&lt;/p&gt;
&lt;p&gt;```go
if issue.RepoID != dep.RepoID {
  if !setting.Service.AllowCrossRepositoryDependencies { ... }
  depRepoPerm, err := access_model.GetDoerRepoPermission(ctx, dep.Repo, ctx.Doer)
  if !depRepoPerm.CanReadIssuesOrPulls(dep.IsPull) {
    return // you can&amp;#39;t see this dependency
  }
}
```&lt;/p&gt;
&lt;p&gt;`RemoveDependency` has no equivalent block at all - it goes straight from resolving `dep` by ID to deleting the link, regardless of which repo `dep` lives in or whether the caller can see it. I confirmed this same code is present in the current latest release, v1.26.4.&lt;/p&gt;
&lt;p&gt;### PoC
Prerequisites: an account with write access to issues on some repo `ownerA/repoA`, and the global numeric issue ID of an issue in a private repo `repoB` that is (or was) legitimately depen…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xv9x-fj9g-vj6h</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2304 — Gitea: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</guid>
    </item>
  </channel>
</rss>
