<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 00:53:23 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-352862</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352862</link>
      <description>EUVD-2026-352862</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352862</guid>
    </item>
    <item>
      <title>fkie_cve-2026-59765</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-59765</link>
      <description>&lt;p&gt;SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-59765</guid>
    </item>
    <item>
      <title>GHSA-2wm4-vwp6-v7xc — Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2wm4-vwp6-v7xc</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea, Go: gitea.dev&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Gitea has robust SSRF protection via `hostmatcher.NewDialContext()` for webhook and migration clone URLs, which validates resolved IPs at the TCP dial level. However, three code paths use raw `http.Get()` (Go&amp;#39;s `DefaultClient`) which completely bypasses this protection, enabling SSRF to internal services and local file read via the `file://` scheme.&lt;/p&gt;
&lt;p&gt;### Vulnerable Code&lt;/p&gt;
&lt;p&gt;**File: `modules/uri/uri.go` (line 32) -- Core vulnerability**&lt;/p&gt;
&lt;p&gt;```go
func Open(uriStr string) (io.ReadCloser, error) {
    u, err := url.Parse(uriStr)
    switch strings.ToLower(u.Scheme) {
    case &amp;#34;http&amp;#34;, &amp;#34;https&amp;#34;:
        f, err := http.Get(uriStr)   // RAW http.Get -- no hostmatcher filtering
        return f.Body, nil
    case &amp;#34;file&amp;#34;:
        return os.Open(u.Path)        // LOCAL FILE READ via file:// scheme
    }
}
```&lt;/p&gt;
&lt;p&gt;**Callers in migration path:**
- `services/migrations/gitea_uploader.go:340` -- `uri.Open(*asset.DownloadURL)` for release assets
- `services/migrations/gitea_uploader.go:586` -- `uri.Open(pr.PatchURL)` for PR patches&lt;/p&gt;
&lt;p&gt;**File: `services/migrations/dump.go` (lines 312, 453)**&lt;/p&gt;
&lt;p&gt;```go
// Line 312 -- release asset download
resp, err := http.Get(*asset.DownloadURL)&lt;/p&gt;
&lt;p&gt;// Line 453 -- PR patch download (with self-documenting TODO)
resp, err := http.Get(u) // TODO: This probably needs to use the downloader
```&lt;/p&gt;
&lt;p&gt;**File: `routers/web/auth/oauth.go` (line 306)**&lt;/p&gt;
&lt;p&gt;```go
func oauth2UpdateAvatarIfNeed(ctx *context.Context, url string, u *user_model.User) {
    resp, err := http.Get(url)…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea, Go: gitea.dev&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Gitea has robust SSRF protection via `hostmatcher.NewDialContext()` for webhook and migration clone URLs, which validates resolved IPs at the TCP dial level. However, three code paths use raw `http.Get()` (Go&amp;#39;s `DefaultClient`) which completely bypasses this protection, enabling SSRF to internal services and local file read via the `file://` scheme.&lt;/p&gt;
&lt;p&gt;### Vulnerable Code&lt;/p&gt;
&lt;p&gt;**File: `modules/uri/uri.go` (line 32) -- Core vulnerability**&lt;/p&gt;
&lt;p&gt;```go
func Open(uriStr string) (io.ReadCloser, error) {
    u, err := url.Parse(uriStr)
    switch strings.ToLower(u.Scheme) {
    case &amp;#34;http&amp;#34;, &amp;#34;https&amp;#34;:
        f, err := http.Get(uriStr)   // RAW http.Get -- no hostmatcher filtering
        return f.Body, nil
    case &amp;#34;file&amp;#34;:
        return os.Open(u.Path)        // LOCAL FILE READ via file:// scheme
    }
}
```&lt;/p&gt;
&lt;p&gt;**Callers in migration path:**
- `services/migrations/gitea_uploader.go:340` -- `uri.Open(*asset.DownloadURL)` for release assets
- `services/migrations/gitea_uploader.go:586` -- `uri.Open(pr.PatchURL)` for PR patches&lt;/p&gt;
&lt;p&gt;**File: `services/migrations/dump.go` (lines 312, 453)**&lt;/p&gt;
&lt;p&gt;```go
// Line 312 -- release asset download
resp, err := http.Get(*asset.DownloadURL)&lt;/p&gt;
&lt;p&gt;// Line 453 -- PR patch download (with self-documenting TODO)
resp, err := http.Get(u) // TODO: This probably needs to use the downloader
```&lt;/p&gt;
&lt;p&gt;**File: `routers/web/auth/oauth.go` (line 306)**&lt;/p&gt;
&lt;p&gt;```go
func oauth2UpdateAvatarIfNeed(ctx *context.Context, url string, u *user_model.User) {
    resp, err := http.Get(url)…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2wm4-vwp6-v7xc</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2304 — Gitea: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</guid>
    </item>
  </channel>
</rss>
