<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 20:37:49 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-352917</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352917</link>
      <description>EUVD-2026-352917</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352917</guid>
    </item>
    <item>
      <title>fkie_cve-2026-58440</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-58440</link>
      <description>&lt;p&gt;Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-58440</guid>
    </item>
    <item>
      <title>GHSA-66m4-5jjr-2rg5 — Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltrati…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-66m4-5jjr-2rg5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: gitea.dev&lt;/p&gt;
&lt;p&gt;## Affected product
Gitea — `services/repository/collaboration.go` (`DeleteCollaboration`) + webhook delivery&lt;/p&gt;
&lt;p&gt;## Summary
When a collaborator with admin permission on a private repo creates a webhook, that webhook keeps firing
after the collaborator&amp;#39;s access is revoked. Gitea&amp;#39;s revocation cleanup `DeleteCollaboration` removes the
collaboration record, recalculates accesses, drops watches, and unassigns issues — but it does **not**
remove or disable webhooks the user created, and webhook delivery never re-checks whether the creator still
has repo access. The former collaborator therefore receives the full payload (issue/comment bodies, commit
data) of all future repository events at their controlled endpoint, indefinitely and invisibly.&lt;/p&gt;
&lt;p&gt;## Affected code
- `services/repository/collaboration.go` → `DeleteCollaboration()` — cleans watches/assignees only; no
  webhook cleanup.
- Webhook delivery path — fires on repo events without re-validating the creator&amp;#39;s current access.&lt;/p&gt;
&lt;p&gt;## Steps to reproduce
Using the provided reproduction materials:
1. Attacker (admin collaborator) creates a webhook → revoke access.
2. Control: `GET /api/v1/repos/admin/wh-repo` (attacker) → **404**.
3. `GET .../hooks` → webhook still `active=true`.
4. Admin creates a new issue **after** revocation → the catcher receives `action:&amp;#34;opened&amp;#34;`,
   `issue.title:&amp;#34;CRITICAL SECRET: …&amp;#34;`, `issue.body` (sentinel private key), `repository.private:true`.
(Runtime-confirmed on `gitea/gitea:1.25.4`. Catcher is an internal…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: gitea.dev&lt;/p&gt;
&lt;p&gt;## Affected product
Gitea — `services/repository/collaboration.go` (`DeleteCollaboration`) + webhook delivery&lt;/p&gt;
&lt;p&gt;## Summary
When a collaborator with admin permission on a private repo creates a webhook, that webhook keeps firing
after the collaborator&amp;#39;s access is revoked. Gitea&amp;#39;s revocation cleanup `DeleteCollaboration` removes the
collaboration record, recalculates accesses, drops watches, and unassigns issues — but it does **not**
remove or disable webhooks the user created, and webhook delivery never re-checks whether the creator still
has repo access. The former collaborator therefore receives the full payload (issue/comment bodies, commit
data) of all future repository events at their controlled endpoint, indefinitely and invisibly.&lt;/p&gt;
&lt;p&gt;## Affected code
- `services/repository/collaboration.go` → `DeleteCollaboration()` — cleans watches/assignees only; no
  webhook cleanup.
- Webhook delivery path — fires on repo events without re-validating the creator&amp;#39;s current access.&lt;/p&gt;
&lt;p&gt;## Steps to reproduce
Using the provided reproduction materials:
1. Attacker (admin collaborator) creates a webhook → revoke access.
2. Control: `GET /api/v1/repos/admin/wh-repo` (attacker) → **404**.
3. `GET .../hooks` → webhook still `active=true`.
4. Admin creates a new issue **after** revocation → the catcher receives `action:&amp;#34;opened&amp;#34;`,
   `issue.title:&amp;#34;CRITICAL SECRET: …&amp;#34;`, `issue.body` (sentinel private key), `repository.private:true`.
(Runtime-confirmed on `gitea/gitea:1.25.4`. Catcher is an internal…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-66m4-5jjr-2rg5</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2304 — Gitea: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</guid>
    </item>
  </channel>
</rss>
