<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 20:38:34 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-352915</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352915</link>
      <description>EUVD-2026-352915</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352915</guid>
    </item>
    <item>
      <title>fkie_cve-2026-58442</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-58442</link>
      <description>&lt;p&gt;Repository migration SSRF via multi-answer DNS allow-list bypass&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Repository migration SSRF via multi-answer DNS allow-list bypass&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-58442</guid>
    </item>
    <item>
      <title>GHSA-h2x6-g7q6-344v — Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-h2x6-g7q6-344v</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Gitea&amp;#39;s repository migration URL validation can be bypassed when a migration hostname resolves to multiple IP addresses. The validation logic accepts the destination if **any** resolved IP is allowed, even if another resolved IP is loopback, private, or otherwise blocked. The later `git clone` operation resolves the hostname again outside of that validation decision, so it can connect to the internal address.&lt;/p&gt;
&lt;p&gt;An authenticated low-privilege user who can create repository migrations can use an attacker-controlled DNS name to make Gitea connect to internal-only Git services and import their contents into a repository controlled by the attacker.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The issue is in `services/migrations/migrate.go`, in the migration allow/block-list check.&lt;/p&gt;
&lt;p&gt;Current logic computes whether any resolved IP is allowed:&lt;/p&gt;
&lt;p&gt;```go
var ipAllowed bool
var ipBlocked bool
for _, addr := range addrList {
    ipAllowed = ipAllowed || allowList.MatchIPAddr(addr)
    ipBlocked = ipBlocked || blockList.MatchIPAddr(addr)
}
```&lt;/p&gt;
&lt;p&gt;Then, when an allow-list is active, the host is accepted if the hostname matches or `ipAllowed` is true:&lt;/p&gt;
&lt;p&gt;```go
if !allowList.IsEmpty() {
    if !allowList.MatchHostName(hostName) &amp;amp;&amp;amp; !ipAllowed {
        return &amp;amp;git.ErrInvalidCloneAddr{Host: hostName, IsPermissionDenied: true}
    }
}
```&lt;/p&gt;
&lt;p&gt;This means a hostname resolving to both:&lt;/p&gt;
&lt;p&gt;- an allowed public IP, e.g. `1.2.3.4`
- a blocked internal IP, e.g. `127.0.0.1`&lt;/p&gt;
&lt;p&gt;passes validation because the public IP sets `ipAllowed =…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Gitea&amp;#39;s repository migration URL validation can be bypassed when a migration hostname resolves to multiple IP addresses. The validation logic accepts the destination if **any** resolved IP is allowed, even if another resolved IP is loopback, private, or otherwise blocked. The later `git clone` operation resolves the hostname again outside of that validation decision, so it can connect to the internal address.&lt;/p&gt;
&lt;p&gt;An authenticated low-privilege user who can create repository migrations can use an attacker-controlled DNS name to make Gitea connect to internal-only Git services and import their contents into a repository controlled by the attacker.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The issue is in `services/migrations/migrate.go`, in the migration allow/block-list check.&lt;/p&gt;
&lt;p&gt;Current logic computes whether any resolved IP is allowed:&lt;/p&gt;
&lt;p&gt;```go
var ipAllowed bool
var ipBlocked bool
for _, addr := range addrList {
    ipAllowed = ipAllowed || allowList.MatchIPAddr(addr)
    ipBlocked = ipBlocked || blockList.MatchIPAddr(addr)
}
```&lt;/p&gt;
&lt;p&gt;Then, when an allow-list is active, the host is accepted if the hostname matches or `ipAllowed` is true:&lt;/p&gt;
&lt;p&gt;```go
if !allowList.IsEmpty() {
    if !allowList.MatchHostName(hostName) &amp;amp;&amp;amp; !ipAllowed {
        return &amp;amp;git.ErrInvalidCloneAddr{Host: hostName, IsPermissionDenied: true}
    }
}
```&lt;/p&gt;
&lt;p&gt;This means a hostname resolving to both:&lt;/p&gt;
&lt;p&gt;- an allowed public IP, e.g. `1.2.3.4`
- a blocked internal IP, e.g. `127.0.0.1`&lt;/p&gt;
&lt;p&gt;passes validation because the public IP sets `ipAllowed =…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-h2x6-g7q6-344v</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2304 — Gitea: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</guid>
    </item>
  </channel>
</rss>
