<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 09:04:13 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-352789</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352789</link>
      <description>EUVD-2026-352789</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352789</guid>
    </item>
    <item>
      <title>fkie_cve-2026-58435</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-58435</link>
      <description>&lt;p&gt;Gitea LFS Deploy-Key Privilege Escalation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Gitea LFS Deploy-Key Privilege Escalation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-58435</guid>
    </item>
    <item>
      <title>GHSA-rh79-75qm-gwjr — Gitea LFS Deploy-Key Privilege Escalation</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rh79-75qm-gwjr</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;## Vulnerability Header&lt;/p&gt;
&lt;p&gt;| Field               | Value                                                       |
| ------------------- | ----------------------------------------------------------- |
| Vulnerability Title | Gitea LFS Deploy-Key Privilege Escalation                   |
| Severity Rating     | High                                                        |
| Bug Category        | Insufficient Authorization                                  |
| Location            | `services/lfs/server.go:268`, `routers/private/serv.go:275` |
| Affected Versions   | 1.25.5                                                      |&lt;/p&gt;
&lt;p&gt;## Executive Summary&lt;/p&gt;
&lt;p&gt;Gitea&amp;#39;s LFS server (`services/lfs/server.go:268`) uses the `UserID` embedded in an LFS JWT to make cross-repository authorization decisions via `LFSObjectAccessible()`. This would be safe if the JWT `UserID` always matched the actual requesting principal — but for deploy keys, `routers/private/serv.go:275` sets `UserID = repo.OwnerID` instead of any identity representing the deploy key itself. As a result, an attacker who holds a write deploy key for any single repo owned by a victim can obtain a legitimate JWT (via the standard SSH `git-lfs-authenticate` flow) that Gitea will honor as if the victim themselves were making the request. The attacker can then exfiltrate LFS objects from any private repo the victim owns — no admin credentials, no server secrets, no brute force required. If the victim is a site administrator, every LFS object…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;## Vulnerability Header&lt;/p&gt;
&lt;p&gt;| Field               | Value                                                       |
| ------------------- | ----------------------------------------------------------- |
| Vulnerability Title | Gitea LFS Deploy-Key Privilege Escalation                   |
| Severity Rating     | High                                                        |
| Bug Category        | Insufficient Authorization                                  |
| Location            | `services/lfs/server.go:268`, `routers/private/serv.go:275` |
| Affected Versions   | 1.25.5                                                      |&lt;/p&gt;
&lt;p&gt;## Executive Summary&lt;/p&gt;
&lt;p&gt;Gitea&amp;#39;s LFS server (`services/lfs/server.go:268`) uses the `UserID` embedded in an LFS JWT to make cross-repository authorization decisions via `LFSObjectAccessible()`. This would be safe if the JWT `UserID` always matched the actual requesting principal — but for deploy keys, `routers/private/serv.go:275` sets `UserID = repo.OwnerID` instead of any identity representing the deploy key itself. As a result, an attacker who holds a write deploy key for any single repo owned by a victim can obtain a legitimate JWT (via the standard SSH `git-lfs-authenticate` flow) that Gitea will honor as if the victim themselves were making the request. The attacker can then exfiltrate LFS objects from any private repo the victim owns — no admin credentials, no server secrets, no brute force required. If the victim is a site administrator, every LFS object…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rh79-75qm-gwjr</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2304 — Gitea: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</guid>
    </item>
  </channel>
</rss>
