Search CVE reports


Toggle filters

61 – 70 of 40452 results

Status is adjusted based on your filters.


CVE-2026-71887

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.86, the high-level OpenPGP API accepted a data signature made by a signing subkey whose Subkey Binding signature carried no embedded Primary Key Binding (cross-certification) signature, in the...

1 affected package

bouncycastle

Package 26.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-71886

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.86, the high-level OpenPGP certificate API accepted a third-party certification or trust delegation from any component key of the issuing certificate, without requiring that component to have...

1 affected package

bouncycastle

Package 26.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-71885

Medium priority
Needs evaluation

In Bouncy Castle for Java before 1.86, the Messaging Layer Security (MLS, RFC 9420) implementation did not bind an X.509 credential to a LeafNode's signature_key. LeafNode.verify() checked a leaf's signature against...

1 affected package

bouncycastle

Package 26.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-66859

Medium priority
Needs evaluation

NULL Pointer Dereference, Use of Uninitialized Variable vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

1 affected package

thrift

Package 26.04 LTS
thrift Needs evaluation
Show less packages

CVE-2026-66858

Medium priority
Needs evaluation

The protocol skip routine in several Apache Thrift bindings did not apply the binding's recursion limit, so a message that nests unknown fields deeply enough can exhaust the stack. Affected: the Python C++ accelerator (the...

3 affected packages

php-horde-thrift, python-thrift, thrift

Package 26.04 LTS
php-horde-thrift Not in release
python-thrift Not in release
thrift Needs evaluation
Show less packages

CVE-2026-66837

Medium priority
Needs evaluation

Stack-based Buffer Overflow, Integer Overflow or Wraparound vulnerability in Apache Thrift php bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

1 affected package

thrift

Package 26.04 LTS
thrift Needs evaluation
Show less packages

CVE-2026-66331

Medium priority
Needs evaluation

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Delphi bindings buffered transport. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which...

1 affected package

thrift

Package 26.04 LTS
thrift Needs evaluation
Show less packages

CVE-2026-66081

Medium priority
Needs evaluation

Access of Uninitialized Pointer vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

1 affected package

thrift

Package 26.04 LTS
thrift Needs evaluation
Show less packages

CVE-2026-66055

Medium priority
Needs evaluation

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift C++, Java, Go, netstd, Python and Delphi bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version...

3 affected packages

libthrift-java, python-thrift, thrift

Package 26.04 LTS
libthrift-java Needs evaluation
python-thrift Not in release
thrift Needs evaluation
Show less packages

CVE-2026-66054

Medium priority
Needs evaluation

Allocation of Resources Without Limits or Throttling, Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.25.0. Users are...

1 affected package

thrift

Package 26.04 LTS
thrift Needs evaluation
Show less packages