Search CVE reports


Toggle filters

41 – 50 of 50631 results

Status is adjusted based on your filters.


CVE-2026-85515

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.86, a truncated OpenPGP encrypted message was accepted with no error reported, and on the SEIPD version 1 path with no integrity check performed at all. RFC 9580 sec. 13.7 permits an...

1 affected package

bouncycastle

Package 20.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-85494

Medium priority
Needs evaluation

Improper handling of length parameter inconsistency, Uncaught exception, Inefficient Algorithmic Complexity, Memory allocation with excessive size value, Initialization of a resource with an insecure default vulnerability in...

4 affected packages

php-horde-thrift, python-thrift, ruby-thrift, thrift

Package 20.04 LTS
php-horde-thrift —
python-thrift —
ruby-thrift Needs evaluation
thrift Needs evaluation
Show less packages

CVE-2026-85493

Medium priority
Needs evaluation

Uncontrolled Recursion vulnerability in Apache Thrift Dart and Java ME bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

1 affected package

thrift

Package 20.04 LTS
thrift Needs evaluation
Show less packages

CVE-2026-85483

Medium priority
Needs evaluation

Use of uninitialized resource, Return of wrong status code vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

1 affected package

thrift

Package 20.04 LTS
thrift Needs evaluation
Show less packages

CVE-2026-85476

Medium priority
Needs evaluation

Loop with unreachable exit condition ('infinite loop') vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

1 affected package

thrift

Package 20.04 LTS
thrift Needs evaluation
Show less packages

CVE-2026-85088

Medium priority
Needs evaluation

Improper Validation of Certificate with Host Mismatch in the C++ and D libraries of Apache Thrift. Both libraries install a default access manager for client sockets — TSSLSocketFactory does so in C++, and the accessManager...

1 affected package

thrift

Package 20.04 LTS
thrift Needs evaluation
Show less packages

CVE-2026-85087

Medium priority
Needs evaluation

Improper certificate validation, Return of wrong status code vulnerability in Apache Thrift python bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

1 affected package

thrift

Package 20.04 LTS
thrift Needs evaluation
Show less packages

CVE-2026-85086

Medium priority
Needs evaluation

Improper certificate validation, Initialization of a resource with an insecure default vulnerability in Apache Thrift perl bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version...

1 affected package

thrift

Package 20.04 LTS
thrift Needs evaluation
Show less packages

CVE-2026-83745

Medium priority
Needs evaluation

Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift nodejs and D lang bindings. Both bindings' WebSocket server transports read the payload length out...

1 affected package

thrift

Package 20.04 LTS
thrift Needs evaluation
Show less packages

CVE-2026-83663

Medium priority
Needs evaluation

Uncontrolled Recursion vulnerability in Apache Thrift go bindings. Both Go transports satisfy a read out of a buffered frame and, when that frame yields no payload bytes, read the next frame and call `Read` again instead...

1 affected package

thrift

Package 20.04 LTS
thrift Needs evaluation
Show less packages