<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 10:41:39 +0000</lastBuildDate>
    <item>
      <title>bdu:2021-02870</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-02870</link>
      <description>bdu:2021-02870</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-02870</guid>
    </item>
    <item>
      <title>certfr-2022-avi-570 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-570</link>
      <description>certfr-2022-avi-570</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-570</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-AE13038 — Security fix for CVE-2019-0210 applied in: spark-sc212-jdk17-py311 3.4.4-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ae13038</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: spark-sc212-jdk17-py311&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the spark-sc212-jdk17-py311 package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: spark-sc212-jdk17-py311&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the spark-sc212-jdk17-py311 package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ae13038</guid>
    </item>
    <item>
      <title>cnvd-2019-41289</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2019-41289</link>
      <description>cnvd-2019-41289</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2019-41289</guid>
    </item>
    <item>
      <title>EUVD-2026-48380</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-48380</link>
      <description>EUVD-2026-48380</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-48380</guid>
    </item>
    <item>
      <title>fkie_cve-2019-0210</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-0210</link>
      <description>&lt;p&gt;In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-0210</guid>
    </item>
    <item>
      <title>GHSA-jq7p-26h5-w78r — Out-of-bounds read in Apache Thrift</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jq7p-26h5-w78r</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/apache/thrift&lt;/p&gt;
&lt;p&gt;In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/apache/thrift&lt;/p&gt;
&lt;p&gt;In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jq7p-26h5-w78r</guid>
    </item>
    <item>
      <title>gsd-2019-0210</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-0210</link>
      <description>gsd-2019-0210</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-0210</guid>
    </item>
    <item>
      <title>OESA-2021-1017 — thrift security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1017</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: thrift&lt;/p&gt;
&lt;p&gt;The Apache Thrift software framework for cross-language services development combines a software stack with a code generation engine to build services that work efficiently and seamlessly between C++, Java, Python, and other languages.\r\n\r\n&#13;
Security Fix(es):\r\n\r\n&#13;
In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in version 0.11.0, depending on the installed version it affects only certain language bindings.(CVE-2019-0205)\r\n\r\n&#13;
In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.(CVE-2019-0210)\r\n\r\n&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: thrift&lt;/p&gt;
&lt;p&gt;The Apache Thrift software framework for cross-language services development combines a software stack with a code generation engine to build services that work efficiently and seamlessly between C++, Java, Python, and other languages.\r\n\r\n&#13;
Security Fix(es):\r\n\r\n&#13;
In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in version 0.11.0, depending on the installed version it affects only certain language bindings.(CVE-2019-0205)\r\n\r\n&#13;
In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.(CVE-2019-0210)\r\n\r\n&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1017</guid>
    </item>
    <item>
      <title>RHSA-2020:0804 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.2.7 on RHEL 6 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:0804</link>
      <description>&lt;p&gt;thrift: Endless loop when feed with specific input data thrift: Out-of-bounds read related to TJSONProtocol or TSimpleJSONProtocol apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default xml-security: Apache Santuario potentially loads XML parsing code from an untrusted source wildfly: The &amp;#39;enabled-protocols&amp;#39; value in legacy security is not respected if OpenSSL security provider is in use netty: HTTP request smuggling netty: HttpObjectDecoder.java allows Content-Length header to accompanied by second Content-Length header netty: HTTP Request Smuggling due to Transfer-Encoding whitespace mishandling&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;thrift: Endless loop when feed with specific input data thrift: Out-of-bounds read related to TJSONProtocol or TSimpleJSONProtocol apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default xml-security: Apache Santuario potentially loads XML parsing code from an untrusted source wildfly: The &amp;#39;enabled-protocols&amp;#39; value in legacy security is not respected if OpenSSL security provider is in use netty: HTTP request smuggling netty: HttpObjectDecoder.java allows Content-Length header to accompanied by second Content-Length header netty: HTTP Request Smuggling due to Transfer-Encoding whitespace mishandling&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:0804</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2019-0210</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-0210</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: thrift&lt;/p&gt;
&lt;p&gt;In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: thrift&lt;/p&gt;
&lt;p&gt;In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-0210</guid>
    </item>
  </channel>
</rss>
