<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 08:00:45 +0000</lastBuildDate>
    <item>
      <title>BIT-thrift-2026-48586 — Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TZlibTransport Decompression…</title>
      <link>https://cve.radiocsirt.org/vuln/bit-thrift-2026-48586</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: thrift&lt;/p&gt;
&lt;p&gt;Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Thrift: before 0.24.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.24.0, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: thrift&lt;/p&gt;
&lt;p&gt;Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Thrift: before 0.24.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.24.0, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-thrift-2026-48586</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1256 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1256</link>
      <description>certfr-2026-avi-1256</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1256</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-CW84944 — Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go,…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-cw84944</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: spark-sc212-jdk17-py311&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the spark-sc212-jdk17-py311 package. Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: spark-sc212-jdk17-py311&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the spark-sc212-jdk17-py311 package. Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-cw84944</guid>
    </item>
    <item>
      <title>EUVD-2026-341198</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-341198</link>
      <description>EUVD-2026-341198</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-341198</guid>
    </item>
    <item>
      <title>fkie_cve-2026-48586</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48586</link>
      <description>&lt;p&gt;Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Thrift: before 0.24.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.24.0, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Thrift: before 0.24.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.24.0, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-48586</guid>
    </item>
    <item>
      <title>GHSA-6h9h-5c4r-fqgf</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6h9h-5c4r-fqgf</link>
      <description>&lt;p&gt;Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Thrift: before 0.24.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.24.0, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Thrift: before 0.24.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.24.0, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6h9h-5c4r-fqgf</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-48586 — Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TZlibTransport Decompression…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-48586</link>
      <description>msrc_CVE-2026-48586</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-48586</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11432-1 — libthrift-0_24_0-0.24.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11432-1</link>
      <description>&lt;p&gt;libthrift-0_24_0-0.24.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libthrift-0_24_0-0.24.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11432-1</guid>
    </item>
    <item>
      <title>RHSA-2026:43581 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:43581</link>
      <description>&lt;p&gt;thrift: org.apache.thrift/libthrift: github.com/apache/thrift: Apache Thrift: Denial of Service via improper handling of highly compressed data golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;thrift: org.apache.thrift/libthrift: github.com/apache/thrift: Apache Thrift: Denial of Service via improper handling of highly compressed data golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:43581</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-48586</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48586</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: libthrift-java, Ubuntu:18.04:LTS: libthrift-java, Ubuntu:20.04:LTS: thrift, Ubuntu:22.04:LTS: libthrift-java, Ubuntu:22.04:LTS: thrift, Ubuntu:24.04:LTS: libthrift-java, Ubuntu:24.04:LTS: thrift, Ubuntu:26.04:LTS: libthrift-java, Ubuntu:26.04:LTS: thrift&lt;/p&gt;
&lt;p&gt;Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: libthrift-java, Ubuntu:18.04:LTS: libthrift-java, Ubuntu:20.04:LTS: thrift, Ubuntu:22.04:LTS: libthrift-java, Ubuntu:22.04:LTS: thrift, Ubuntu:24.04:LTS: libthrift-java, Ubuntu:24.04:LTS: thrift, Ubuntu:26.04:LTS: libthrift-java, Ubuntu:26.04:LTS: thrift&lt;/p&gt;
&lt;p&gt;Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48586</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2834 — Red Hat Build of Apache Camel for Quarkus (sshd-core, libthrift, org.hl7.fhir.utilities): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2834</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux und Apache Camel ausnutzen, um einen Denial of Service Angriff durchzuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren und offenzulegen oder beliebigen Code auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux und Apache Camel ausnutzen, um einen Denial of Service Angriff durchzuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren und offenzulegen oder beliebigen Code auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2834</guid>
    </item>
  </channel>
</rss>
