<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 06:12:16 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-352869</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352869</link>
      <description>EUVD-2026-352869</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352869</guid>
    </item>
    <item>
      <title>fkie_cve-2026-58445</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-58445</link>
      <description>&lt;p&gt;Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-58445</guid>
    </item>
    <item>
      <title>GHSA-pgqf-926r-548m — Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pgqf-926r-548m</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The API endpoint `DELETE /repos/{owner}/{repo}/issues/{index}/labels/{id}` loads the label by ID with a **global,
unscoped** lookup and never verifies the label belongs to the URL&amp;#39;s repository (or its owning organization). Because
the response status differs by whether the label ID exists **anywhere on the instance** (204) versus not (422), an
authenticated user can use the endpoint as a **cross-repository label-ID existence / enumeration oracle**, including
for labels in repositories and organizations they cannot access.&lt;/p&gt;
&lt;p&gt;## Severity&lt;/p&gt;
&lt;p&gt;- The leaked information is minimal (existence/count of label IDs instance-wide); **no label name, color, or owning
  repository is disclosed, and no cross-repository write occurs.**&lt;/p&gt;
&lt;p&gt;## Affected / patched versions&lt;/p&gt;
&lt;p&gt;- **Affected:** through **1.26.3** (latest at time of report).
- **Patched:** none yet.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;`DeleteIssueLabel` resolves the label with a global loader and never checks its scope:&lt;/p&gt;
&lt;p&gt;```go
// routers/api/v1/repo/issue_label.go  (DeleteIssueLabel)
label, err := issues_model.GetLabelByID(ctx, ctx.PathParamInt64(&amp;#34;id&amp;#34;))   // global, unscoped
```&lt;/p&gt;
&lt;p&gt;`GetLabelByID` (`models/issues/label.go`) is `e.ID(labelID).Get(l)` with **no** `repo_id` / `org_id` filter. The
handler never verifies `label.RepoID == ctx.Repo.Repository.ID` (nor the org-label equivalent), and the downstream
`issue_service.RemoveLabel` (`services/issue/label.go`) only re-checks the doer&amp;#39;s write permission on the **issue&amp;#39;s
own** repository — never that the…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The API endpoint `DELETE /repos/{owner}/{repo}/issues/{index}/labels/{id}` loads the label by ID with a **global,
unscoped** lookup and never verifies the label belongs to the URL&amp;#39;s repository (or its owning organization). Because
the response status differs by whether the label ID exists **anywhere on the instance** (204) versus not (422), an
authenticated user can use the endpoint as a **cross-repository label-ID existence / enumeration oracle**, including
for labels in repositories and organizations they cannot access.&lt;/p&gt;
&lt;p&gt;## Severity&lt;/p&gt;
&lt;p&gt;- The leaked information is minimal (existence/count of label IDs instance-wide); **no label name, color, or owning
  repository is disclosed, and no cross-repository write occurs.**&lt;/p&gt;
&lt;p&gt;## Affected / patched versions&lt;/p&gt;
&lt;p&gt;- **Affected:** through **1.26.3** (latest at time of report).
- **Patched:** none yet.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;`DeleteIssueLabel` resolves the label with a global loader and never checks its scope:&lt;/p&gt;
&lt;p&gt;```go
// routers/api/v1/repo/issue_label.go  (DeleteIssueLabel)
label, err := issues_model.GetLabelByID(ctx, ctx.PathParamInt64(&amp;#34;id&amp;#34;))   // global, unscoped
```&lt;/p&gt;
&lt;p&gt;`GetLabelByID` (`models/issues/label.go`) is `e.ID(labelID).Get(l)` with **no** `repo_id` / `org_id` filter. The
handler never verifies `label.RepoID == ctx.Repo.Repository.ID` (nor the org-label equivalent), and the downstream
`issue_service.RemoveLabel` (`services/issue/label.go`) only re-checks the doer&amp;#39;s write permission on the **issue&amp;#39;s
own** repository — never that the…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pgqf-926r-548m</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2304 — Gitea: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</guid>
    </item>
  </channel>
</rss>
