<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 00:52:51 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-352916</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352916</link>
      <description>EUVD-2026-352916</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352916</guid>
    </item>
    <item>
      <title>fkie_cve-2026-58441</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-58441</link>
      <description>&lt;p&gt;SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-58441</guid>
    </item>
    <item>
      <title>GHSA-xmj7-xj85-hfc3 — Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xmj7-xj85-hfc3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;### Summary
Gitea&amp;#39;s `restore-repo` CLI command restores a repository from a dump
directory/archive. When parsing `pull_request.yml` from that dump, the
`Head.CloneURL` field is used to add a git remote and fetch from it with
no validation, because the safety check that&amp;#39;s supposed to guard it
(`CheckAndEnsureSafePR`) is called with an empty `commonCloneBaseURL`,
which silently disables it. This lets a malicious dump make the Gitea
server execute `git fetch` against an attacker-chosen URL (SSRF), or
disclose a local git repository via `file://`. This is a different root
cause from the recently fixed path-traversal issue in the same command
(#38215), which patched `DownloadURL`/`PatchURL` but not `Head.CloneURL`.&lt;/p&gt;
&lt;p&gt;### Details
`services/migrations/restore.go`&amp;#39;s `GetPullRequests()` unmarshals
`pull_request.yml` directly into `base.PullRequest` structs with no
validation of `Head.CloneURL`:&lt;/p&gt;
&lt;p&gt;```go
err = yaml.Unmarshal(bs, &amp;amp;pulls)
...
for _, pr := range pulls {
    if pr.PatchURL != &amp;#34;&amp;#34; {
        pr.PatchURL = &amp;#34;file://&amp;#34; + util.FilePathJoinAbs(r.baseDir, pr.PatchURL)
    }
    CheckAndEnsureSafePR(pr, &amp;#34;&amp;#34;, r)   // &amp;lt;-- empty baseURL
}
```&lt;/p&gt;
&lt;p&gt;`CheckAndEnsureSafePR` (`services/migrations/common.go`) is supposed to
reject `Head.CloneURL`/`PatchURL` values that don&amp;#39;t share a common base
URL:&lt;/p&gt;
&lt;p&gt;```go
func hasBaseURL(toCheck, baseURL string) bool {
    if len(baseURL) &amp;gt; 0 &amp;amp;&amp;amp; baseURL[len(baseURL)-1] != &amp;#39;/&amp;#39; {
        baseURL += &amp;#34;/&amp;#34;
    }
    return strings.HasPrefix(toCheck, baseURL)
}&lt;/p&gt;
&lt;p&gt;func Chec…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;### Summary
Gitea&amp;#39;s `restore-repo` CLI command restores a repository from a dump
directory/archive. When parsing `pull_request.yml` from that dump, the
`Head.CloneURL` field is used to add a git remote and fetch from it with
no validation, because the safety check that&amp;#39;s supposed to guard it
(`CheckAndEnsureSafePR`) is called with an empty `commonCloneBaseURL`,
which silently disables it. This lets a malicious dump make the Gitea
server execute `git fetch` against an attacker-chosen URL (SSRF), or
disclose a local git repository via `file://`. This is a different root
cause from the recently fixed path-traversal issue in the same command
(#38215), which patched `DownloadURL`/`PatchURL` but not `Head.CloneURL`.&lt;/p&gt;
&lt;p&gt;### Details
`services/migrations/restore.go`&amp;#39;s `GetPullRequests()` unmarshals
`pull_request.yml` directly into `base.PullRequest` structs with no
validation of `Head.CloneURL`:&lt;/p&gt;
&lt;p&gt;```go
err = yaml.Unmarshal(bs, &amp;amp;pulls)
...
for _, pr := range pulls {
    if pr.PatchURL != &amp;#34;&amp;#34; {
        pr.PatchURL = &amp;#34;file://&amp;#34; + util.FilePathJoinAbs(r.baseDir, pr.PatchURL)
    }
    CheckAndEnsureSafePR(pr, &amp;#34;&amp;#34;, r)   // &amp;lt;-- empty baseURL
}
```&lt;/p&gt;
&lt;p&gt;`CheckAndEnsureSafePR` (`services/migrations/common.go`) is supposed to
reject `Head.CloneURL`/`PatchURL` values that don&amp;#39;t share a common base
URL:&lt;/p&gt;
&lt;p&gt;```go
func hasBaseURL(toCheck, baseURL string) bool {
    if len(baseURL) &amp;gt; 0 &amp;amp;&amp;amp; baseURL[len(baseURL)-1] != &amp;#39;/&amp;#39; {
        baseURL += &amp;#34;/&amp;#34;
    }
    return strings.HasPrefix(toCheck, baseURL)
}&lt;/p&gt;
&lt;p&gt;func Chec…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xmj7-xj85-hfc3</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2304 — Gitea: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</guid>
    </item>
  </channel>
</rss>
