<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T20:12:07.693107+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-02870</id>
    <title>bdu:2021-02870</title>
    <updated>2026-10-03T20:12:07.988766+00:00</updated>
    <content>bdu:2021-02870</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-02870"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-570</id>
    <title>certfr-2022-avi-570 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T20:12:07.988836+00:00</updated>
    <content>certfr-2022-avi-570</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-570"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ae13038</id>
    <title>CLEANSTART-2026-AE13038 — Security fix for CVE-2019-0210 applied in: spark-sc212-jdk17-py311 3.4.4-r0</title>
    <updated>2026-10-03T20:12:07.988856+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: spark-sc212-jdk17-py311</p>
<p>Security vulnerability affects the spark-sc212-jdk17-py311 package. This issue is resolved in later releases. See references for vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ae13038"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2019-41289</id>
    <title>cnvd-2019-41289</title>
    <updated>2026-10-03T20:12:07.988889+00:00</updated>
    <content>cnvd-2019-41289</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2019-41289"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-48380</id>
    <title>EUVD-2026-48380</title>
    <updated>2026-10-03T20:12:07.988902+00:00</updated>
    <content>EUVD-2026-48380</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-48380"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2019-0210</id>
    <title>fkie_cve-2019-0210</title>
    <updated>2026-10-03T20:12:07.988913+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2019-0210"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jq7p-26h5-w78r</id>
    <title>GHSA-jq7p-26h5-w78r — Out-of-bounds read in Apache Thrift</title>
    <updated>2026-10-03T20:12:07.988934+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/apache/thrift</p>
<p>In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jq7p-26h5-w78r"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2019-0210</id>
    <title>gsd-2019-0210</title>
    <updated>2026-10-03T20:12:07.988953+00:00</updated>
    <content>gsd-2019-0210</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2019-0210"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1017</id>
    <title>OESA-2021-1017 — thrift security update</title>
    <updated>2026-10-03T20:12:07.988964+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: thrift</p>
<p>The Apache Thrift software framework for cross-language services development combines a software stack with a code generation engine to build services that work efficiently and seamlessly between C++, Java, Python, and other languages.\r\n\r\n
Security Fix(es):\r\n\r\n
In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in version 0.11.0, depending on the installed version it affects only certain language bindings.(CVE-2019-0205)\r\n\r\n
In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.(CVE-2019-0210)\r\n\r\n</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1017"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2020:0804</id>
    <title>RHSA-2020:0804 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.2.7 on RHEL 6 security update</title>
    <updated>2026-10-03T20:12:07.988986+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>thrift: Endless loop when feed with specific input data thrift: Out-of-bounds read related to TJSONProtocol or TSimpleJSONProtocol apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default xml-security: Apache Santuario potentially loads XML parsing code from an untrusted source wildfly: The 'enabled-protocols' value in legacy security is not respected if OpenSSL security provider is in use netty: HTTP request smuggling netty: HttpObjectDecoder.java allows Content-Length header to accompanied by second Content-Length header netty: HTTP Request Smuggling due to Transfer-Encoding whitespace mishandling</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2020:0804"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-0210</id>
    <title>Withdrawn: UBUNTU-CVE-2019-0210</title>
    <updated>2026-10-03T20:12:07.989015+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> Ubuntu:20.04:LTS: thrift</p>
<p>In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-0210"/>
  </entry>
</feed>
