<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://127.0.0.1:10001/rss/recent/cvelistv5/10</id>
  <title>Most recent entries from cvelistv5</title>
  <updated>2026-10-03T16:09:19.485935+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>info@circl.lu</email>
  </author>
  <link href="https://127.0.0.1:10001" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://127.0.0.1:10001/vuln/cve-2026-66331</id>
    <title>cve-2026-66331</title>
    <updated>2026-10-03T15:52:56.858000+00:00</updated>
    <content>Apache Thrift: Buffered transport reads are not accounted against MaxMessageSize</content>
    <link href="https://127.0.0.1:10001/vuln/cve-2026-66331"/>
    <published>2026-10-02T12:32:46.166000+00:00</published>
  </entry>
  <entry>
    <id>https://127.0.0.1:10001/vuln/cve-2026-66055</id>
    <title>cve-2026-66055</title>
    <updated>2026-10-03T15:52:56.729000+00:00</updated>
    <content>Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TJSONProtocol accepts a single JSON string/number exceeding the configured size limit (multi-language)</content>
    <link href="https://127.0.0.1:10001/vuln/cve-2026-66055"/>
    <published>2026-10-02T12:49:40.955000+00:00</published>
  </entry>
  <entry>
    <id>https://127.0.0.1:10001/vuln/cve-2026-63772</id>
    <title>cve-2026-63772</title>
    <updated>2026-10-03T15:52:56.607000+00:00</updated>
    <content>Apache Thrift: Unauthenticated single-packet crash of Go Thrift servers via the THeader transform count</content>
    <link href="https://127.0.0.1:10001/vuln/cve-2026-63772"/>
    <published>2026-10-02T12:52:07.427000+00:00</published>
  </entry>
  <entry>
    <id>https://127.0.0.1:10001/vuln/cve-2026-61374</id>
    <title>cve-2026-61374</title>
    <updated>2026-10-03T15:52:56.479000+00:00</updated>
    <content>Apache Thrift: Java TSaslTransport post-auth data-frame missing size limit</content>
    <link href="https://127.0.0.1:10001/vuln/cve-2026-61374"/>
    <published>2026-10-02T12:53:00.477000+00:00</published>
  </entry>
  <entry>
    <id>https://127.0.0.1:10001/vuln/cve-2026-66054</id>
    <title>cve-2026-66054</title>
    <updated>2026-10-03T15:52:56.354000+00:00</updated>
    <content>Apache Thrift: C++ THeaderTransport does not enforce configured maxFrameSize</content>
    <link href="https://127.0.0.1:10001/vuln/cve-2026-66054"/>
    <published>2026-10-02T12:58:05.610000+00:00</published>
  </entry>
  <entry>
    <id>https://127.0.0.1:10001/vuln/cve-2026-101104</id>
    <title>cve-2026-101104</title>
    <updated>2026-10-03T15:52:56.225000+00:00</updated>
    <content>Missing Authorization in Meari IoT Cloud Platform OpenAPI Service</content>
    <link href="https://127.0.0.1:10001/vuln/cve-2026-101104"/>
    <published>2026-10-02T15:58:21.626000+00:00</published>
  </entry>
  <entry>
    <id>https://127.0.0.1:10001/vuln/cve-2026-104910</id>
    <title>cve-2026-104910</title>
    <updated>2026-10-03T15:52:56.095000+00:00</updated>
    <content>MISP Information Disclosure via Related Events Listing Bypassing Per-Event Authorization</content>
    <link href="https://127.0.0.1:10001/vuln/cve-2026-104910"/>
    <published>2026-10-02T16:01:32.781000+00:00</published>
  </entry>
  <entry>
    <id>https://127.0.0.1:10001/vuln/cve-2026-96613</id>
    <title>cve-2026-96613</title>
    <updated>2026-10-03T15:52:55.965000+00:00</updated>
    <content>Missing Authorization in Meari IoT Cloud Platform OpenAPI Service</content>
    <link href="https://127.0.0.1:10001/vuln/cve-2026-96613"/>
    <published>2026-10-02T16:03:04.281000+00:00</published>
  </entry>
  <entry>
    <id>https://127.0.0.1:10001/vuln/cve-2026-104912</id>
    <title>cve-2026-104912</title>
    <updated>2026-10-03T15:52:55.841000+00:00</updated>
    <content>MISP Correlation Authorization Bypass Exposes Restricted Event and Attribute Data</content>
    <link href="https://127.0.0.1:10001/vuln/cve-2026-104912"/>
    <published>2026-10-02T16:04:50.580000+00:00</published>
  </entry>
  <entry>
    <id>https://127.0.0.1:10001/vuln/cve-2026-103648</id>
    <title>cve-2026-103648</title>
    <updated>2026-10-03T15:52:55.709000+00:00</updated>
    <content>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in image-downloader</content>
    <link href="https://127.0.0.1:10001/vuln/cve-2026-103648"/>
    <published>2026-10-02T16:05:25.331000+00:00</published>
  </entry>
</feed>
