<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T13:39:00.795945+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-thrift-2026-66053</id>
    <title>BIT-thrift-2026-66053 — Apache Thrift: Python TSSLSocket Hostname Matcher Import</title>
    <updated>2026-10-02T13:39:00.888682+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: thrift</p>
<p>Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.</p>
<p>This issue affects Apache Thrift: before 0.24.0.</p>
<p>Users are recommended to upgrade to version 0.24.0, which fixes the issue.</p>
<p>This replaces CVE-2026-41603</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-thrift-2026-66053"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-evernote-backup-cve-2026-66053</id>
    <title>BREW-evernote-backup-CVE-2026-66053 — Apache Thrift Python bindings have a Improper Validation of Certificate with Host Mismatch vulnerabilit</title>
    <updated>2026-10-02T13:39:00.888746+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: evernote-backup</p>
<p>Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.</p>
<p>This issue affects Apache Thrift: before 0.24.0.</p>
<p>Users are recommended to upgrade to version 0.24.0, which fixes the issue.</p>
<p>This replaces CVE-2026-41603</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-evernote-backup-cve-2026-66053"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</id>
    <title>certfr-2026-avi-1094 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T13:39:00.888793+00:00</updated>
    <content>certfr-2026-avi-1094</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-341206</id>
    <title>EUVD-2026-341206</title>
    <updated>2026-10-02T13:39:00.888830+00:00</updated>
    <content>EUVD-2026-341206</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-341206"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-66053</id>
    <title>fkie_cve-2026-66053</title>
    <updated>2026-10-02T13:39:00.888850+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.</p>
<p>This issue affects Apache Thrift: before 0.24.0.</p>
<p>Users are recommended to upgrade to version 0.24.0, which fixes the issue.</p>
<p>This replaces CVE-2026-41603</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-66053"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hwrj-9rr4-24xh</id>
    <title>GHSA-hwrj-9rr4-24xh — Apache Thrift Python bindings have a Improper Validation of Certificate with Host Mismatch vulnerabilit</title>
    <updated>2026-10-02T13:39:00.888890+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: thrift</p>
<p>Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.</p>
<p>This issue affects Apache Thrift: before 0.24.0.</p>
<p>Users are recommended to upgrade to version 0.24.0, which fixes the issue.</p>
<p>This replaces CVE-2026-41603</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hwrj-9rr4-24xh"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-66053</id>
    <title>msrc_CVE-2026-66053 — Apache Thrift: Python TSSLSocket Hostname Matcher Import</title>
    <updated>2026-10-02T13:39:00.888931+00:00</updated>
    <content>msrc_CVE-2026-66053</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-66053"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-3927</id>
    <title>PYSEC-2026-3927 — Apache Thrift Python bindings have a Improper Validation of Certificate with Host Mismatch vulnerabilit</title>
    <updated>2026-10-02T13:39:00.888961+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: thrift</p>
<p>Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.</p>
<p>This issue affects Apache Thrift: before 0.24.0.</p>
<p>Users are recommended to upgrade to version 0.24.0, which fixes the issue.</p>
<p>This replaces CVE-2026-41603</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-3927"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:49837</id>
    <title>RHSA-2026:49837 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-02T13:39:00.889005+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>thrift: Apache Thrift Python bindings: Denial of Service via data amplification thrift: Apache Thrift: Denial of Service via infinite loop thrift: Apache Thrift: Denial of Service due to uncontrolled resource allocation thrift: Apache Thrift Ruby bindings: Denial of Service via improper handling of highly compressed data thrift: Apache Thrift Node.js bindings: Denial of Service due to inefficient algorithmic complexity and resource allocation thrift: Apache Thrift C++ bindings: Information disclosure due to buffer over-read vulnerability thrift: Apache Thrift C++ bindings: Remote code execution via heap-based buffer overflow thrift: Apache Thrift: Information disclosure and denial of service due to out-of-bounds read thrift: Apache Thrift Python bindings: Information disclosure due to improper certificate validation</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:49837"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-66053</id>
    <title>UBUNTU-CVE-2026-66053</title>
    <updated>2026-10-02T13:39:00.889066+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: python-thrift, Ubuntu:18.04:LTS: python-thrift, Ubuntu:20.04:LTS: thrift, Ubuntu:22.04:LTS: thrift, Ubuntu:24.04:LTS: thrift, Ubuntu:26.04:LTS: thrift</p>
<p>Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. This replaces CVE-2026-41603</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-66053"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3043</id>
    <title>WID-SEC-W-2026-3043 — IBM QRadar SIEM: Mehrere Schwachstellen</title>
    <updated>2026-10-02T13:39:00.889116+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um seine Privilegien zu erhöhen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen und um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3043"/>
  </entry>
</feed>
