<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:04:09 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-352872</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352872</link>
      <description>EUVD-2026-352872</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352872</guid>
    </item>
    <item>
      <title>fkie_cve-2026-58437</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-58437</link>
      <description>&lt;p&gt;Repository Visibility Manipulation via Git Push Options&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Repository Visibility Manipulation via Git Push Options&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-58437</guid>
    </item>
    <item>
      <title>GHSA-8p9h-49rc-qgxj — Gitea: Repository Visibility Manipulation via Git Push Options</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8p9h-49rc-qgxj</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;### Repository Visibility Manipulation via Git Push Options&lt;/p&gt;
&lt;p&gt;| Field | Value |
|-------|-------|
| **Affected File** | `routers/private/hook_post_receive.go` |
| **Affected Function** | `HookPostReceive()` |
| **Affected Lines** | 173–225 |
| **Prerequisite** | Attacker must have owner-level or admin collaborator access to the target repository |&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;#### Description&lt;/p&gt;
&lt;p&gt;Gitea&amp;#39;s post-receive git hook handler processes git push options — key-value pairs transmitted by a client during `git push` using the `-o` flag. Two undocumented push options, `repo.private` and `repo.template`, allow any user with repository owner or admin-collaborator access to toggle the visibility (`private/public`) and template status of a repository as a side effect of a normal git push.&lt;/p&gt;
&lt;p&gt;This capability was originally intended solely for the &amp;#34;push-to-create&amp;#34; feature (automatically creating a repo on first push). However, the options are processed without restriction on already-existing repositories, and — critically — the visibility change bypasses every control that a proper settings change would trigger:&lt;/p&gt;
&lt;p&gt;- No entry written to the repository&amp;#39;s audit/activity log
- No webhook event fired (`repository` event with `visibility_changed` action)
- No org-level notification to owners
- No team permission re-calculation
- No email alert to watchers
- The database update uses `UpdateRepositoryColsNoAutoTime`, which also suppresses the `updated_at` timestamp change&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;#### Vulnerable Code&lt;/p&gt;
&lt;p&gt;**`routers/priv…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;### Repository Visibility Manipulation via Git Push Options&lt;/p&gt;
&lt;p&gt;| Field | Value |
|-------|-------|
| **Affected File** | `routers/private/hook_post_receive.go` |
| **Affected Function** | `HookPostReceive()` |
| **Affected Lines** | 173–225 |
| **Prerequisite** | Attacker must have owner-level or admin collaborator access to the target repository |&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;#### Description&lt;/p&gt;
&lt;p&gt;Gitea&amp;#39;s post-receive git hook handler processes git push options — key-value pairs transmitted by a client during `git push` using the `-o` flag. Two undocumented push options, `repo.private` and `repo.template`, allow any user with repository owner or admin-collaborator access to toggle the visibility (`private/public`) and template status of a repository as a side effect of a normal git push.&lt;/p&gt;
&lt;p&gt;This capability was originally intended solely for the &amp;#34;push-to-create&amp;#34; feature (automatically creating a repo on first push). However, the options are processed without restriction on already-existing repositories, and — critically — the visibility change bypasses every control that a proper settings change would trigger:&lt;/p&gt;
&lt;p&gt;- No entry written to the repository&amp;#39;s audit/activity log
- No webhook event fired (`repository` event with `visibility_changed` action)
- No org-level notification to owners
- No team permission re-calculation
- No email alert to watchers
- The database update uses `UpdateRepositoryColsNoAutoTime`, which also suppresses the `updated_at` timestamp change&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;#### Vulnerable Code&lt;/p&gt;
&lt;p&gt;**`routers/priv…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8p9h-49rc-qgxj</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2304 — Gitea: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</guid>
    </item>
  </channel>
</rss>
