<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T18:36:52.524451+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-thrift-2026-48586</id>
    <title>BIT-thrift-2026-48586 — Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TZlibTransport Decompression…</title>
    <updated>2026-10-02T18:36:53.557825+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: thrift</p>
<p>Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings.</p>
<p>This issue affects Apache Thrift: before 0.24.0.</p>
<p>Users are recommended to upgrade to version 0.24.0, which fixes the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-thrift-2026-48586"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1256</id>
    <title>certfr-2026-avi-1256 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T18:36:53.557910+00:00</updated>
    <content>certfr-2026-avi-1256</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1256"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-cw84944</id>
    <title>CLEANSTART-2026-CW84944 — Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go,…</title>
    <updated>2026-10-02T18:36:53.557931+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: spark-sc212-jdk17-py311</p>
<p>Security vulnerability affects the spark-sc212-jdk17-py311 package. Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-cw84944"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-341198</id>
    <title>EUVD-2026-341198</title>
    <updated>2026-10-02T18:36:53.557955+00:00</updated>
    <content>EUVD-2026-341198</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-341198"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48586</id>
    <title>fkie_cve-2026-48586</title>
    <updated>2026-10-02T18:36:53.557969+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings.</p>
<p>This issue affects Apache Thrift: before 0.24.0.</p>
<p>Users are recommended to upgrade to version 0.24.0, which fixes the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-48586"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6h9h-5c4r-fqgf</id>
    <title>GHSA-6h9h-5c4r-fqgf</title>
    <updated>2026-10-02T18:36:53.557992+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings.</p>
<p>This issue affects Apache Thrift: before 0.24.0.</p>
<p>Users are recommended to upgrade to version 0.24.0, which fixes the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6h9h-5c4r-fqgf"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-48586</id>
    <title>msrc_CVE-2026-48586 — Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TZlibTransport Decompression…</title>
    <updated>2026-10-02T18:36:53.558008+00:00</updated>
    <content>msrc_CVE-2026-48586</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-48586"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11432-1</id>
    <title>openSUSE-SU-2026:11432-1 — libthrift-0_24_0-0.24.0-1.1 on GA media</title>
    <updated>2026-10-02T18:36:53.558025+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libthrift-0_24_0-0.24.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11432-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:43581</id>
    <title>RHSA-2026:43581 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-02T18:36:53.558047+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>thrift: org.apache.thrift/libthrift: github.com/apache/thrift: Apache Thrift: Denial of Service via improper handling of highly compressed data golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:43581"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48586</id>
    <title>UBUNTU-CVE-2026-48586</title>
    <updated>2026-10-02T18:36:53.558066+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: libthrift-java, Ubuntu:18.04:LTS: libthrift-java, Ubuntu:20.04:LTS: thrift, Ubuntu:22.04:LTS: libthrift-java, Ubuntu:22.04:LTS: thrift, Ubuntu:24.04:LTS: libthrift-java, Ubuntu:24.04:LTS: thrift, Ubuntu:26.04:LTS: libthrift-java, Ubuntu:26.04:LTS: thrift</p>
<p>Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48586"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2834</id>
    <title>WID-SEC-W-2026-2834 — Red Hat Build of Apache Camel for Quarkus (sshd-core, libthrift, org.hl7.fhir.utilities): Mehrere Schwachstellen</title>
    <updated>2026-10-02T18:36:53.558097+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux und Apache Camel ausnutzen, um einen Denial of Service Angriff durchzuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren und offenzulegen oder beliebigen Code auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2834"/>
  </entry>
</feed>
