<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 22:08:46 +0000</lastBuildDate>
    <item>
      <title>BIT-thrift-2026-43871 — Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-count limit</title>
      <link>https://cve.radiocsirt.org/vuln/bit-thrift-2026-43871</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: thrift&lt;/p&gt;
&lt;p&gt;Loop with Unreachable Exit Condition (&amp;#39;Infinite Loop&amp;#39;) vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.24.0, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: thrift&lt;/p&gt;
&lt;p&gt;Loop with Unreachable Exit Condition (&amp;#39;Infinite Loop&amp;#39;) vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.24.0, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-thrift-2026-43871</guid>
    </item>
    <item>
      <title>BREW-evernote-backup-CVE-2026-43871 — Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop</title>
      <link>https://cve.radiocsirt.org/vuln/brew-evernote-backup-cve-2026-43871</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: evernote-backup&lt;/p&gt;
&lt;p&gt;Loop with Unreachable Exit Condition (&amp;#39;Infinite Loop&amp;#39;) vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.24.0, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: evernote-backup&lt;/p&gt;
&lt;p&gt;Loop with Unreachable Exit Condition (&amp;#39;Infinite Loop&amp;#39;) vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.24.0, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-evernote-backup-cve-2026-43871</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1256 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1256</link>
      <description>certfr-2026-avi-1256</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1256</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-AP36720 — Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ap36720</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: tempo&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the tempo package. Loop with Unreachable Exit Condition (&amp;#39;Infinite Loop&amp;#39;) vulnerability in Apache Thrift Python, Go, PHP and Java bindings.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: tempo&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the tempo package. Loop with Unreachable Exit Condition (&amp;#39;Infinite Loop&amp;#39;) vulnerability in Apache Thrift Python, Go, PHP and Java bindings.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ap36720</guid>
    </item>
    <item>
      <title>EUVD-2026-341195</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-341195</link>
      <description>EUVD-2026-341195</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-341195</guid>
    </item>
    <item>
      <title>fkie_cve-2026-43871</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-43871</link>
      <description>&lt;p&gt;Loop with Unreachable Exit Condition (&amp;#39;Infinite Loop&amp;#39;) vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.24.0, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Loop with Unreachable Exit Condition (&amp;#39;Infinite Loop&amp;#39;) vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.24.0, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-43871</guid>
    </item>
    <item>
      <title>GHSA-8wv5-x4w7-5gww — Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8wv5-x4w7-5gww</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: thrift, Go: github.com/apache/thrift, Packagist: apache/thrift, Maven: org.apache.thrift:libthrift&lt;/p&gt;
&lt;p&gt;Loop with Unreachable Exit Condition (&amp;#39;Infinite Loop&amp;#39;) vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.24.0, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: thrift, Go: github.com/apache/thrift, Packagist: apache/thrift, Maven: org.apache.thrift:libthrift&lt;/p&gt;
&lt;p&gt;Loop with Unreachable Exit Condition (&amp;#39;Infinite Loop&amp;#39;) vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.24.0, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8wv5-x4w7-5gww</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-43871 — Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-count limit</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-43871</link>
      <description>msrc_CVE-2026-43871</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-43871</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11432-1 — libthrift-0_24_0-0.24.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11432-1</link>
      <description>&lt;p&gt;libthrift-0_24_0-0.24.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libthrift-0_24_0-0.24.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11432-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-3926 — Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-3926</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: thrift&lt;/p&gt;
&lt;p&gt;Loop with Unreachable Exit Condition (&amp;#39;Infinite Loop&amp;#39;) vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.24.0, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: thrift&lt;/p&gt;
&lt;p&gt;Loop with Unreachable Exit Condition (&amp;#39;Infinite Loop&amp;#39;) vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.24.0, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-3926</guid>
    </item>
    <item>
      <title>RHSA-2026:49837 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:49837</link>
      <description>&lt;p&gt;thrift: Apache Thrift Python bindings: Denial of Service via data amplification thrift: Apache Thrift: Denial of Service via infinite loop thrift: Apache Thrift: Denial of Service due to uncontrolled resource allocation thrift: Apache Thrift Ruby bindings: Denial of Service via improper handling of highly compressed data thrift: Apache Thrift Node.js bindings: Denial of Service due to inefficient algorithmic complexity and resource allocation thrift: Apache Thrift C++ bindings: Information disclosure due to buffer over-read vulnerability thrift: Apache Thrift C++ bindings: Remote code execution via heap-based buffer overflow thrift: Apache Thrift: Information disclosure and denial of service due to out-of-bounds read thrift: Apache Thrift Python bindings: Information disclosure due to improper certificate validation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;thrift: Apache Thrift Python bindings: Denial of Service via data amplification thrift: Apache Thrift: Denial of Service via infinite loop thrift: Apache Thrift: Denial of Service due to uncontrolled resource allocation thrift: Apache Thrift Ruby bindings: Denial of Service via improper handling of highly compressed data thrift: Apache Thrift Node.js bindings: Denial of Service due to inefficient algorithmic complexity and resource allocation thrift: Apache Thrift C++ bindings: Information disclosure due to buffer over-read vulnerability thrift: Apache Thrift C++ bindings: Remote code execution via heap-based buffer overflow thrift: Apache Thrift: Information disclosure and denial of service due to out-of-bounds read thrift: Apache Thrift Python bindings: Information disclosure due to improper certificate validation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:49837</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-43871</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43871</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: libthrift-java, Ubuntu:18.04:LTS: libthrift-java, Ubuntu:20.04:LTS: thrift, Ubuntu:22.04:LTS: libthrift-java, Ubuntu:22.04:LTS: thrift, Ubuntu:24.04:LTS: libthrift-java, Ubuntu:24.04:LTS: thrift, Ubuntu:26.04:LTS: libthrift-java, Ubuntu:26.04:LTS: thrift&lt;/p&gt;
&lt;p&gt;Loop with Unreachable Exit Condition (&amp;#39;Infinite Loop&amp;#39;) vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: libthrift-java, Ubuntu:18.04:LTS: libthrift-java, Ubuntu:20.04:LTS: thrift, Ubuntu:22.04:LTS: libthrift-java, Ubuntu:22.04:LTS: thrift, Ubuntu:24.04:LTS: libthrift-java, Ubuntu:24.04:LTS: thrift, Ubuntu:26.04:LTS: libthrift-java, Ubuntu:26.04:LTS: thrift&lt;/p&gt;
&lt;p&gt;Loop with Unreachable Exit Condition (&amp;#39;Infinite Loop&amp;#39;) vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43871</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3595 — IBM QRadar SIEM: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3595</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um beliebigen Programmcode auszuführen, um seine Privilegien zu erhöhen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um beliebigen Programmcode auszuführen, um seine Privilegien zu erhöhen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3595</guid>
    </item>
  </channel>
</rss>
