Search CVE reports


Toggle filters

51 – 60 of 49529 results

Status is adjusted based on your filters.


CVE-2026-83745

Medium priority
Needs evaluation

Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift nodejs and D lang bindings. Both bindings' WebSocket server transports read the payload length out...

1 affected package

thrift

Package 24.04 LTS
thrift Needs evaluation
Show less packages

CVE-2026-83663

Medium priority
Needs evaluation

Uncontrolled Recursion vulnerability in Apache Thrift go bindings. Both Go transports satisfy a read out of a buffered frame and, when that frame yields no payload bytes, read the next frame and call `Read` again instead...

1 affected package

thrift

Package 24.04 LTS
thrift Needs evaluation
Show less packages

CVE-2026-83632

Medium priority
Needs evaluation

Allocation of resources without limits or throttling, Integer overflow or wraparound, Heap-based buffer overflow vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to...

1 affected package

thrift

Package 24.04 LTS
thrift Needs evaluation
Show less packages

CVE-2026-82459

Medium priority
Needs evaluation

Integer underflow (wrap or wraparound), Out-of-bounds write vulnerability in Apache Thrift C++ 32 bit THeaderTransport. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which...

1 affected package

thrift

Package 24.04 LTS
thrift Needs evaluation
Show less packages

CVE-2026-82458

Medium priority
Needs evaluation

Memory allocation with excessive size value, Allocation of resources without limits or throttling vulnerability in Apache Thrift Go, netstd, OCaml, Erlang, JavaME, Rust, C++, Java, Kotlin and D language bindings. This issue...

2 affected packages

libthrift-java, thrift

Package 24.04 LTS
libthrift-java Needs evaluation
thrift Needs evaluation
Show less packages

CVE-2026-71892

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.86, the opt-in key-size validation on CMS key-transport recipients, org.bouncycastle.cms.jcajce.JceKeyTransRecipient.setKeySizeValidation(true), never ran for a message using RFC 9709...

1 affected package

bouncycastle

Package 24.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-71891

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.86, BLS12_381BasicScheme.keyValidate, and so BLSPublicKeyParameters and every BasicScheme, MessageAugmentation and ProofOfPossession verify and aggregateVerify that gate on it, accepted a public...

1 affected package

bouncycastle

Package 24.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-71890

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.86, validation of an MLS (RFC 9420) external commit's proposal list, org.bouncycastle.mls.protocol.Group.validateExternalCachedProposals, counted the proposals by type and bounded the removed...

1 affected package

bouncycastle

Package 24.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-71889

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.86, neither copy of PKIXCertPathReviewer - org.bouncycastle.pkix.jcajce.PKIXCertPathReviewer nor the legacy org.bouncycastle.x509.PKIXCertPathReviewer - applied X.509 name constraints to the...

1 affected package

bouncycastle

Package 24.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-71888

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.86, the streaming CMS AuthenticatedData parser accepted a message whose digestAlgorithm and authAttrs fields disagreed about whether authenticated attributes were present. RFC 5652 sec. 9.1 pairs...

1 affected package

bouncycastle

Package 24.04 LTS
bouncycastle Needs evaluation
Show less packages