<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 00:06:59 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-382336</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-382336</link>
      <description>EUVD-2026-382336</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-382336</guid>
    </item>
    <item>
      <title>fkie_cve-2026-83745</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-83745</link>
      <description>&lt;p&gt;Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift 
nodejs and D lang bindings.&lt;/p&gt;
&lt;p&gt;Both bindings&amp;#39; WebSocket server transports read the payload length out of the frame header and allocate that many bytes immediately, without checking that the bytes have arrived. A single ~14-byte frame therefore commits as much memory as it cares to declare -- measured at 513 MiB against the Node.js server and 2 GiB against the D transport -- and in the Node.js case the connection is left open afterwards, so the frame can simply be sent again.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Thrift before 0.25.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.25.0, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift 
nodejs and D lang bindings.&lt;/p&gt;
&lt;p&gt;Both bindings&amp;#39; WebSocket server transports read the payload length out of the frame header and allocate that many bytes immediately, without checking that the bytes have arrived. A single ~14-byte frame therefore commits as much memory as it cares to declare -- measured at 513 MiB against the Node.js server and 2 GiB against the D transport -- and in the Node.js case the connection is left open afterwards, so the frame can simply be sent again.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Thrift before 0.25.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.25.0, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-83745</guid>
    </item>
    <item>
      <title>GHSA-5jgj-9r28-q5fp</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5jgj-9r28-q5fp</link>
      <description>&lt;p&gt;Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift 
nodejs and D lang bindings.&lt;/p&gt;
&lt;p&gt;Both bindings&amp;#39; WebSocket server transports read the payload length out of the frame header and allocate that many bytes immediately, without checking that the bytes have arrived. A single ~14-byte frame therefore commits as much memory as it cares to declare -- measured at 513 MiB against the Node.js server and 2 GiB against the D transport -- and in the Node.js case the connection is left open afterwards, so the frame can simply be sent again.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Thrift before 0.25.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.25.0, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift 
nodejs and D lang bindings.&lt;/p&gt;
&lt;p&gt;Both bindings&amp;#39; WebSocket server transports read the payload length out of the frame header and allocate that many bytes immediately, without checking that the bytes have arrived. A single ~14-byte frame therefore commits as much memory as it cares to declare -- measured at 513 MiB against the Node.js server and 2 GiB against the D transport -- and in the Node.js case the connection is left open afterwards, so the frame can simply be sent again.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Thrift before 0.25.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.25.0, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5jgj-9r28-q5fp</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-83745 — Apache Thrift, Apache Thrift: WebSocket frame decoders allocate the payload buffer from the declared length, not the by…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-83745</link>
      <description>msrc_CVE-2026-83745</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-83745</guid>
    </item>
    <item>
      <title>RHSA-2026:74369 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:74369</link>
      <description>&lt;p&gt;thrift: thrift: Denial of Service via improper handling of compressed data thrift: thrift: Denial of Service via uninitialized pointer access in c_glib bindings thrift: thrift: Denial of Service via excessive resource allocation in Delphi buffered transport thrift: thrift: Denial of Service via buffer overflow in PHP bindings thrift: Apache Thrift: Denial of Service via deeply nested unknown fields thrift: thrift: Denial of Service via excessive memory allocation thrift: thrift: Denial of Service via integer underflow in THeaderTransport thrift: thrift: Denial of Service via excessive memory allocation in WebSocket transport thrift: thrift: Information disclosure via improper certificate validation in Perl bindings thrift: thrift: Man-in-the-middle attacks via improper certificate validation thrift: thrift: Denial of Service via improper message handling in language bindings thrift: thrift: Denial of Service via TJSONProtocol in Node.js bindings thrift: thrift: Denial of Service via infinite loop in D language bindings thrift: thrift: Denial of Service via improper exception handling in TNonblockingServer thrift: thrift: Denial of Service via stack-based buffer overflow in THeaderProtocol thrift: thrift: Denial of Service via memory leak in THeaderTransport thrift: thrift: Denial of Service via excessive memory allocation in Dart bindings thrift: thrift: Denial of Service via improper length parameter handling in Lua bindings thrift: Apache Thrift: Denial of Service via unco…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;thrift: thrift: Denial of Service via improper handling of compressed data thrift: thrift: Denial of Service via uninitialized pointer access in c_glib bindings thrift: thrift: Denial of Service via excessive resource allocation in Delphi buffered transport thrift: thrift: Denial of Service via buffer overflow in PHP bindings thrift: Apache Thrift: Denial of Service via deeply nested unknown fields thrift: thrift: Denial of Service via excessive memory allocation thrift: thrift: Denial of Service via integer underflow in THeaderTransport thrift: thrift: Denial of Service via excessive memory allocation in WebSocket transport thrift: thrift: Information disclosure via improper certificate validation in Perl bindings thrift: thrift: Man-in-the-middle attacks via improper certificate validation thrift: thrift: Denial of Service via improper message handling in language bindings thrift: thrift: Denial of Service via TJSONProtocol in Node.js bindings thrift: thrift: Denial of Service via infinite loop in D language bindings thrift: thrift: Denial of Service via improper exception handling in TNonblockingServer thrift: thrift: Denial of Service via stack-based buffer overflow in THeaderProtocol thrift: thrift: Denial of Service via memory leak in THeaderTransport thrift: thrift: Denial of Service via excessive memory allocation in Dart bindings thrift: thrift: Denial of Service via improper length parameter handling in Lua bindings thrift: Apache Thrift: Denial of Service via unco…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:74369</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-83745</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-83745</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: thrift, Ubuntu:22.04:LTS: thrift, Ubuntu:24.04:LTS: thrift, Ubuntu:26.04:LTS: thrift&lt;/p&gt;
&lt;p&gt;Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift nodejs and D lang bindings. Both bindings&amp;#39; WebSocket server transports read the payload length out of the frame header and allocate that many bytes immediately, without checking that the bytes have arrived. A single ~14-byte frame therefore commits as much memory as it cares to declare -- measured at 513 MiB against the Node.js server and 2 GiB against the D transport -- and in the Node.js case the connection is left open afterwards, so the frame can simply be sent again. This issue affects Apache Thrift before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: thrift, Ubuntu:22.04:LTS: thrift, Ubuntu:24.04:LTS: thrift, Ubuntu:26.04:LTS: thrift&lt;/p&gt;
&lt;p&gt;Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift nodejs and D lang bindings. Both bindings&amp;#39; WebSocket server transports read the payload length out of the frame header and allocate that many bytes immediately, without checking that the bytes have arrived. A single ~14-byte frame therefore commits as much memory as it cares to declare -- measured at 513 MiB against the Node.js server and 2 GiB against the D transport -- and in the Node.js case the connection is left open afterwards, so the frame can simply be sent again. This issue affects Apache Thrift before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-83745</guid>
    </item>
  </channel>
</rss>
