<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 14:57:38 +0000</lastBuildDate>
    <item>
      <title>BIT-thrift-2026-45112 — Apache Thrift: Unbounded Read Leading to Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/bit-thrift-2026-45112</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: thrift&lt;/p&gt;
&lt;p&gt;Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Thrift: from 0.19.0 before 0.24.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.24.0, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: thrift&lt;/p&gt;
&lt;p&gt;Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Thrift: from 0.19.0 before 0.24.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.24.0, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-thrift-2026-45112</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-QF48371 — Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-qf48371</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: spark-sc212-jdk17-py311&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the spark-sc212-jdk17-py311 package. Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: spark-sc212-jdk17-py311&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the spark-sc212-jdk17-py311 package. Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-qf48371</guid>
    </item>
    <item>
      <title>EUVD-2026-341196</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-341196</link>
      <description>EUVD-2026-341196</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-341196</guid>
    </item>
    <item>
      <title>fkie_cve-2026-45112</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45112</link>
      <description>&lt;p&gt;Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Thrift: from 0.19.0 before 0.24.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.24.0, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Thrift: from 0.19.0 before 0.24.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.24.0, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-45112</guid>
    </item>
    <item>
      <title>GHSA-g9fj-fh28-776p</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g9fj-fh28-776p</link>
      <description>&lt;p&gt;Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Thrift: from 0.19.0 before 0.24.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.24.0, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Thrift: from 0.19.0 before 0.24.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.24.0, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g9fj-fh28-776p</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11432-1 — libthrift-0_24_0-0.24.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11432-1</link>
      <description>&lt;p&gt;libthrift-0_24_0-0.24.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libthrift-0_24_0-0.24.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11432-1</guid>
    </item>
    <item>
      <title>RHSA-2026:49837 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:49837</link>
      <description>&lt;p&gt;thrift: Apache Thrift Python bindings: Denial of Service via data amplification thrift: Apache Thrift: Denial of Service via infinite loop thrift: Apache Thrift: Denial of Service due to uncontrolled resource allocation thrift: Apache Thrift Ruby bindings: Denial of Service via improper handling of highly compressed data thrift: Apache Thrift Node.js bindings: Denial of Service due to inefficient algorithmic complexity and resource allocation thrift: Apache Thrift C++ bindings: Information disclosure due to buffer over-read vulnerability thrift: Apache Thrift C++ bindings: Remote code execution via heap-based buffer overflow thrift: Apache Thrift: Information disclosure and denial of service due to out-of-bounds read thrift: Apache Thrift Python bindings: Information disclosure due to improper certificate validation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;thrift: Apache Thrift Python bindings: Denial of Service via data amplification thrift: Apache Thrift: Denial of Service via infinite loop thrift: Apache Thrift: Denial of Service due to uncontrolled resource allocation thrift: Apache Thrift Ruby bindings: Denial of Service via improper handling of highly compressed data thrift: Apache Thrift Node.js bindings: Denial of Service due to inefficient algorithmic complexity and resource allocation thrift: Apache Thrift C++ bindings: Information disclosure due to buffer over-read vulnerability thrift: Apache Thrift C++ bindings: Remote code execution via heap-based buffer overflow thrift: Apache Thrift: Information disclosure and denial of service due to out-of-bounds read thrift: Apache Thrift Python bindings: Information disclosure due to improper certificate validation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:49837</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-45112</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-45112</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: libthrift-java, Ubuntu:18.04:LTS: libthrift-java, Ubuntu:22.04:LTS: libthrift-java, Ubuntu:24.04:LTS: libthrift-java, Ubuntu:26.04:LTS: libthrift-java&lt;/p&gt;
&lt;p&gt;Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: from 0.19.0 before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: libthrift-java, Ubuntu:18.04:LTS: libthrift-java, Ubuntu:22.04:LTS: libthrift-java, Ubuntu:24.04:LTS: libthrift-java, Ubuntu:26.04:LTS: libthrift-java&lt;/p&gt;
&lt;p&gt;Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: from 0.19.0 before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-45112</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2834 — Red Hat Build of Apache Camel for Quarkus (sshd-core, libthrift, org.hl7.fhir.utilities): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2834</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux und Apache Camel ausnutzen, um einen Denial of Service Angriff durchzuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren und offenzulegen oder beliebigen Code auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux und Apache Camel ausnutzen, um einen Denial of Service Angriff durchzuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren und offenzulegen oder beliebigen Code auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2834</guid>
    </item>
  </channel>
</rss>
