<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 16:21:46 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-352914</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352914</link>
      <description>EUVD-2026-352914</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352914</guid>
    </item>
    <item>
      <title>fkie_cve-2026-58443</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-58443</link>
      <description>&lt;p&gt;Public-only repository tokens can update private PR head branches&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Public-only repository tokens can update private PR head branches&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-58443</guid>
    </item>
    <item>
      <title>GHSA-xxjv-752h-3vp2 — Gitea: Public-only repository tokens can update private PR head branches</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xxjv-752h-3vp2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;### Summary
Gitea allows a `public-only,write:repository` token to update a private pull request head branch through a public base repository route.&lt;/p&gt;
&lt;p&gt;The vulnerable endpoint is:&lt;/p&gt;
&lt;p&gt;```text
POST /api/v1/repos/{public-owner}/{public-repo}/pulls/{index}/update
```&lt;/p&gt;
&lt;p&gt;Gitea checks the token&amp;#39;s public-only restriction against the route repository, which is the public base repository. `UpdatePullRequest()` then authorizes the pull request head repository with ordinary user RBAC and calls the pull update service. If the head repository is private, the active token&amp;#39;s public-only restriction is not re-applied to that private repository before Gitea pushes changes into it.&lt;/p&gt;
&lt;p&gt;As a result, the same token that cannot directly write to the private repository can still cause Gitea to push public base commits into the private head branch.&lt;/p&gt;
&lt;p&gt;### Details
The pull request API routes are attached under a repository route group. The public-only check applies to `ctx.Repo.Repository`, the route/base repository.&lt;/p&gt;
&lt;p&gt;```go
// routers/api/v1/api.go:1358-1394
					m.Group(&amp;#34;/pulls&amp;#34;, func() {
						m.Combo(&amp;#34;&amp;#34;).Get(repo.ListPullRequests).
							Post(reqToken(), mustNotBeArchived, bind(api.CreatePullRequestOption{}), repo.CreatePullRequest)
						m.Get(&amp;#34;/pinned&amp;#34;, repo.ListPinnedPullRequests)
						m.Post(&amp;#34;/comments/{id}/resolve&amp;#34;, reqToken(), mustNotBeArchived, repo.ResolvePullReviewComment)
						m.Post(&amp;#34;/comments/{id}/unresolve&amp;#34;, reqToken(), mustNotBeArchived, repo.UnresolvePullReviewComment)
						m.Group(&amp;#34;/{in…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;### Summary
Gitea allows a `public-only,write:repository` token to update a private pull request head branch through a public base repository route.&lt;/p&gt;
&lt;p&gt;The vulnerable endpoint is:&lt;/p&gt;
&lt;p&gt;```text
POST /api/v1/repos/{public-owner}/{public-repo}/pulls/{index}/update
```&lt;/p&gt;
&lt;p&gt;Gitea checks the token&amp;#39;s public-only restriction against the route repository, which is the public base repository. `UpdatePullRequest()` then authorizes the pull request head repository with ordinary user RBAC and calls the pull update service. If the head repository is private, the active token&amp;#39;s public-only restriction is not re-applied to that private repository before Gitea pushes changes into it.&lt;/p&gt;
&lt;p&gt;As a result, the same token that cannot directly write to the private repository can still cause Gitea to push public base commits into the private head branch.&lt;/p&gt;
&lt;p&gt;### Details
The pull request API routes are attached under a repository route group. The public-only check applies to `ctx.Repo.Repository`, the route/base repository.&lt;/p&gt;
&lt;p&gt;```go
// routers/api/v1/api.go:1358-1394
					m.Group(&amp;#34;/pulls&amp;#34;, func() {
						m.Combo(&amp;#34;&amp;#34;).Get(repo.ListPullRequests).
							Post(reqToken(), mustNotBeArchived, bind(api.CreatePullRequestOption{}), repo.CreatePullRequest)
						m.Get(&amp;#34;/pinned&amp;#34;, repo.ListPinnedPullRequests)
						m.Post(&amp;#34;/comments/{id}/resolve&amp;#34;, reqToken(), mustNotBeArchived, repo.ResolvePullReviewComment)
						m.Post(&amp;#34;/comments/{id}/unresolve&amp;#34;, reqToken(), mustNotBeArchived, repo.UnresolvePullReviewComment)
						m.Group(&amp;#34;/{in…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xxjv-752h-3vp2</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2304 — Gitea: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</guid>
    </item>
  </channel>
</rss>
