<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:32:40 +0000</lastBuildDate>
    <item>
      <title>BIT-thrift-2026-66053 — Apache Thrift: Python TSSLSocket Hostname Matcher Import</title>
      <link>https://cve.radiocsirt.org/vuln/bit-thrift-2026-66053</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: thrift&lt;/p&gt;
&lt;p&gt;Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Thrift: before 0.24.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.24.0, which fixes the issue.&lt;/p&gt;
&lt;p&gt;This replaces CVE-2026-41603&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: thrift&lt;/p&gt;
&lt;p&gt;Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Thrift: before 0.24.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.24.0, which fixes the issue.&lt;/p&gt;
&lt;p&gt;This replaces CVE-2026-41603&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-thrift-2026-66053</guid>
    </item>
    <item>
      <title>BREW-evernote-backup-CVE-2026-66053 — Apache Thrift Python bindings have a Improper Validation of Certificate with Host Mismatch vulnerabilit</title>
      <link>https://cve.radiocsirt.org/vuln/brew-evernote-backup-cve-2026-66053</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: evernote-backup&lt;/p&gt;
&lt;p&gt;Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Thrift: before 0.24.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.24.0, which fixes the issue.&lt;/p&gt;
&lt;p&gt;This replaces CVE-2026-41603&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: evernote-backup&lt;/p&gt;
&lt;p&gt;Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Thrift: before 0.24.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.24.0, which fixes the issue.&lt;/p&gt;
&lt;p&gt;This replaces CVE-2026-41603&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-evernote-backup-cve-2026-66053</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1094 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</link>
      <description>certfr-2026-avi-1094</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</guid>
    </item>
    <item>
      <title>EUVD-2026-341206</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-341206</link>
      <description>EUVD-2026-341206</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-341206</guid>
    </item>
    <item>
      <title>fkie_cve-2026-66053</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-66053</link>
      <description>&lt;p&gt;Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Thrift: before 0.24.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.24.0, which fixes the issue.&lt;/p&gt;
&lt;p&gt;This replaces CVE-2026-41603&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Thrift: before 0.24.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.24.0, which fixes the issue.&lt;/p&gt;
&lt;p&gt;This replaces CVE-2026-41603&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-66053</guid>
    </item>
    <item>
      <title>GHSA-hwrj-9rr4-24xh — Apache Thrift Python bindings have a Improper Validation of Certificate with Host Mismatch vulnerabilit</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hwrj-9rr4-24xh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: thrift&lt;/p&gt;
&lt;p&gt;Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Thrift: before 0.24.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.24.0, which fixes the issue.&lt;/p&gt;
&lt;p&gt;This replaces CVE-2026-41603&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: thrift&lt;/p&gt;
&lt;p&gt;Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Thrift: before 0.24.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.24.0, which fixes the issue.&lt;/p&gt;
&lt;p&gt;This replaces CVE-2026-41603&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hwrj-9rr4-24xh</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-66053 — Apache Thrift: Python TSSLSocket Hostname Matcher Import</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-66053</link>
      <description>msrc_CVE-2026-66053</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-66053</guid>
    </item>
    <item>
      <title>PYSEC-2026-3927 — Apache Thrift Python bindings have a Improper Validation of Certificate with Host Mismatch vulnerabilit</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-3927</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: thrift&lt;/p&gt;
&lt;p&gt;Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Thrift: before 0.24.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.24.0, which fixes the issue.&lt;/p&gt;
&lt;p&gt;This replaces CVE-2026-41603&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: thrift&lt;/p&gt;
&lt;p&gt;Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Thrift: before 0.24.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.24.0, which fixes the issue.&lt;/p&gt;
&lt;p&gt;This replaces CVE-2026-41603&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-3927</guid>
    </item>
    <item>
      <title>RHSA-2026:49837 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:49837</link>
      <description>&lt;p&gt;thrift: Apache Thrift Python bindings: Denial of Service via data amplification thrift: Apache Thrift: Denial of Service via infinite loop thrift: Apache Thrift: Denial of Service due to uncontrolled resource allocation thrift: Apache Thrift Ruby bindings: Denial of Service via improper handling of highly compressed data thrift: Apache Thrift Node.js bindings: Denial of Service due to inefficient algorithmic complexity and resource allocation thrift: Apache Thrift C++ bindings: Information disclosure due to buffer over-read vulnerability thrift: Apache Thrift C++ bindings: Remote code execution via heap-based buffer overflow thrift: Apache Thrift: Information disclosure and denial of service due to out-of-bounds read thrift: Apache Thrift Python bindings: Information disclosure due to improper certificate validation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;thrift: Apache Thrift Python bindings: Denial of Service via data amplification thrift: Apache Thrift: Denial of Service via infinite loop thrift: Apache Thrift: Denial of Service due to uncontrolled resource allocation thrift: Apache Thrift Ruby bindings: Denial of Service via improper handling of highly compressed data thrift: Apache Thrift Node.js bindings: Denial of Service due to inefficient algorithmic complexity and resource allocation thrift: Apache Thrift C++ bindings: Information disclosure due to buffer over-read vulnerability thrift: Apache Thrift C++ bindings: Remote code execution via heap-based buffer overflow thrift: Apache Thrift: Information disclosure and denial of service due to out-of-bounds read thrift: Apache Thrift Python bindings: Information disclosure due to improper certificate validation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:49837</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-66053</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-66053</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: python-thrift, Ubuntu:18.04:LTS: python-thrift, Ubuntu:20.04:LTS: thrift, Ubuntu:22.04:LTS: thrift, Ubuntu:24.04:LTS: thrift, Ubuntu:26.04:LTS: thrift&lt;/p&gt;
&lt;p&gt;Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. This replaces CVE-2026-41603&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: python-thrift, Ubuntu:18.04:LTS: python-thrift, Ubuntu:20.04:LTS: thrift, Ubuntu:22.04:LTS: thrift, Ubuntu:24.04:LTS: thrift, Ubuntu:26.04:LTS: thrift&lt;/p&gt;
&lt;p&gt;Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. This replaces CVE-2026-41603&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-66053</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3043 — IBM QRadar SIEM: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3043</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um seine Privilegien zu erhöhen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen und um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um seine Privilegien zu erhöhen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen und um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3043</guid>
    </item>
  </channel>
</rss>
