<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:05:33 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-352871</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352871</link>
      <description>EUVD-2026-352871</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352871</guid>
    </item>
    <item>
      <title>fkie_cve-2026-58444</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-58444</link>
      <description>&lt;p&gt;Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-58444</guid>
    </item>
    <item>
      <title>GHSA-cp3q-vrj2-ghhh — Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses pri…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cp3q-vrj2-ghhh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;### Summary
A personal access token (PAT) or OAuth2 token that does **not** carry the
`repository` scope or that is **public-only** is correctly rejected (HTTP 403)
by the recently hardened web content routes (archive download, raw/media file
download, and repository RSS/Atom feeds). However, the repository home page route
`GET /{owner}/{repo}` (handler `repo.Home`) serves the **private** repository&amp;#39;s
rendered README, root file/directory tree, description, language statistics,
license, and latest-release information to that same token.&lt;/p&gt;
&lt;p&gt;This is a token-scope enforcement bypass and private-repository content
disclosure. It is the same source→sink pattern already fixed for neighbouring
routes in:&lt;/p&gt;
&lt;p&gt;- **GHSA-cr4g-f395-h25h** (CVE-2026-20706) token scope bypass on web archive download
- **GHSA-3pww-vcvm-3gmj** (CVE-2026-27761) token scope bypass on repository RSS/Atom feeds&lt;/p&gt;
&lt;p&gt;`repo.Home` is the remaining token-auth-enabled content route that was not given
the guard.&lt;/p&gt;
&lt;p&gt;### Details / Root cause
Web routes accept token authentication only when explicitly opted in with
`webAuth.AllowBasic` / `webAuth.AllowOAuth2`. The repository home route carries
`AllowBasic` (added so that `go get` can resolve private modules):&lt;/p&gt;
&lt;p&gt;```go
// routers/web/web.go:1256
m.Get(&amp;#34;/{username}/{reponame}&amp;#34;, optSignIn, webAuth.AllowBasic,
      context.RepoAssignment, context.RepoRefByType(git.RefTypeBranch),
      repo.SetEditorconfigIfExists, repo.Home)
```&lt;/p&gt;
&lt;p&gt;When a PAT/OAuth2 token is supplied via HTTP Basic auth,…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;### Summary
A personal access token (PAT) or OAuth2 token that does **not** carry the
`repository` scope or that is **public-only** is correctly rejected (HTTP 403)
by the recently hardened web content routes (archive download, raw/media file
download, and repository RSS/Atom feeds). However, the repository home page route
`GET /{owner}/{repo}` (handler `repo.Home`) serves the **private** repository&amp;#39;s
rendered README, root file/directory tree, description, language statistics,
license, and latest-release information to that same token.&lt;/p&gt;
&lt;p&gt;This is a token-scope enforcement bypass and private-repository content
disclosure. It is the same source→sink pattern already fixed for neighbouring
routes in:&lt;/p&gt;
&lt;p&gt;- **GHSA-cr4g-f395-h25h** (CVE-2026-20706) token scope bypass on web archive download
- **GHSA-3pww-vcvm-3gmj** (CVE-2026-27761) token scope bypass on repository RSS/Atom feeds&lt;/p&gt;
&lt;p&gt;`repo.Home` is the remaining token-auth-enabled content route that was not given
the guard.&lt;/p&gt;
&lt;p&gt;### Details / Root cause
Web routes accept token authentication only when explicitly opted in with
`webAuth.AllowBasic` / `webAuth.AllowOAuth2`. The repository home route carries
`AllowBasic` (added so that `go get` can resolve private modules):&lt;/p&gt;
&lt;p&gt;```go
// routers/web/web.go:1256
m.Get(&amp;#34;/{username}/{reponame}&amp;#34;, optSignIn, webAuth.AllowBasic,
      context.RepoAssignment, context.RepoRefByType(git.RefTypeBranch),
      repo.SetEditorconfigIfExists, repo.Home)
```&lt;/p&gt;
&lt;p&gt;When a PAT/OAuth2 token is supplied via HTTP Basic auth,…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cp3q-vrj2-ghhh</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2304 — Gitea: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen, Sitzungen zu übernehmen oder wiederzuverwenden oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2304</guid>
    </item>
  </channel>
</rss>
