<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 09:04:23 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-352793</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352793</link>
      <description>EUVD-2026-352793</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352793</guid>
    </item>
    <item>
      <title>fkie_cve-2026-58428</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-58428</link>
      <description>&lt;p&gt;Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-58428</guid>
    </item>
    <item>
      <title>GHSA-25gq-j9jx-43pg — Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-25gq-j9jx-43pg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The web handler `EditReleasePost` (`routers/web/repo/release.go`) reads form fields with prefix `attachment-edit-{uuid}` into a `map[uuid]newName`, passes that map to `release_service.UpdateRelease`, which writes the new name to the database via `repo_model.UpdateAttachmentByUUID` WITHOUT calling `upload.Verify` against `setting.Repository.Release.AllowedTypes`. The parent CVE-2025-68939 fix (PR #32151) added the equivalent `upload.Verify` call on the API edit endpoints via `attachment_service.UpdateAttachment`. The web release edit path was not updated.&lt;/p&gt;
&lt;p&gt;A user with repository write permission can rename any existing release attachment to a name with a forbidden extension via the web release edit form, bypassing the operator-configured allowlist.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;### Vulnerable code&lt;/p&gt;
&lt;p&gt;`routers/web/repo/release.go:597` `EditReleasePost`:&lt;/p&gt;
&lt;p&gt;```go
const editPrefix = &amp;#34;attachment-edit-&amp;#34;
editAttachments := make(map[string]string)
if setting.Attachment.Enabled {
    for k, v := range ctx.Req.Form {
        if strings.HasPrefix(k, editPrefix) {
            editAttachments[k[len(editPrefix):]] = v[0]
        }
    }
}
...
if err = release_service.UpdateRelease(ctx, ctx.Doer, ctx.Repo.GitRepo,
    rel, addAttachmentUUIDs, delAttachmentUUIDs, editAttachments); err != nil {
    ctx.ServerError(&amp;#34;UpdateRelease&amp;#34;, err)
    return
}
```&lt;/p&gt;
&lt;p&gt;`services/release/release.go:321` -- the unvalidated write:&lt;/p&gt;
&lt;p&gt;```go
for uuid, newName := range editAttachments {
    if !deletedUUIDs.Contains(uuid) {…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The web handler `EditReleasePost` (`routers/web/repo/release.go`) reads form fields with prefix `attachment-edit-{uuid}` into a `map[uuid]newName`, passes that map to `release_service.UpdateRelease`, which writes the new name to the database via `repo_model.UpdateAttachmentByUUID` WITHOUT calling `upload.Verify` against `setting.Repository.Release.AllowedTypes`. The parent CVE-2025-68939 fix (PR #32151) added the equivalent `upload.Verify` call on the API edit endpoints via `attachment_service.UpdateAttachment`. The web release edit path was not updated.&lt;/p&gt;
&lt;p&gt;A user with repository write permission can rename any existing release attachment to a name with a forbidden extension via the web release edit form, bypassing the operator-configured allowlist.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;### Vulnerable code&lt;/p&gt;
&lt;p&gt;`routers/web/repo/release.go:597` `EditReleasePost`:&lt;/p&gt;
&lt;p&gt;```go
const editPrefix = &amp;#34;attachment-edit-&amp;#34;
editAttachments := make(map[string]string)
if setting.Attachment.Enabled {
    for k, v := range ctx.Req.Form {
        if strings.HasPrefix(k, editPrefix) {
            editAttachments[k[len(editPrefix):]] = v[0]
        }
    }
}
...
if err = release_service.UpdateRelease(ctx, ctx.Doer, ctx.Repo.GitRepo,
    rel, addAttachmentUUIDs, delAttachmentUUIDs, editAttachments); err != nil {
    ctx.ServerError(&amp;#34;UpdateRelease&amp;#34;, err)
    return
}
```&lt;/p&gt;
&lt;p&gt;`services/release/release.go:321` -- the unvalidated write:&lt;/p&gt;
&lt;p&gt;```go
for uuid, newName := range editAttachments {
    if !deletedUUIDs.Contains(uuid) {…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-25gq-j9jx-43pg</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2304 — Gitea: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</guid>
    </item>
  </channel>
</rss>
