<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from cvelistv5</title>
    <link>https://127.0.0.1:10001</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 17:54:38 +0000</lastBuildDate>
    <item>
      <title>cve-2026-66331</title>
      <link>https://127.0.0.1:10001/vuln/cve-2026-66331</link>
      <description>Apache Thrift: Buffered transport reads are not accounted against MaxMessageSize</description>
      <content:encoded>Apache Thrift: Buffered transport reads are not accounted against MaxMessageSize</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/cve-2026-66331</guid>
      <pubDate>Fri, 02 Oct 2026 12:32:46 +0000</pubDate>
    </item>
    <item>
      <title>cve-2026-66055</title>
      <link>https://127.0.0.1:10001/vuln/cve-2026-66055</link>
      <description>Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TJSONProtocol accepts a single JSON string/number exceeding the configured size limit (multi-language)</description>
      <content:encoded>Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TJSONProtocol accepts a single JSON string/number exceeding the configured size limit (multi-language)</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/cve-2026-66055</guid>
      <pubDate>Fri, 02 Oct 2026 12:49:40 +0000</pubDate>
    </item>
    <item>
      <title>cve-2026-63772</title>
      <link>https://127.0.0.1:10001/vuln/cve-2026-63772</link>
      <description>Apache Thrift: Unauthenticated single-packet crash of Go Thrift servers via the THeader transform count</description>
      <content:encoded>Apache Thrift: Unauthenticated single-packet crash of Go Thrift servers via the THeader transform count</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/cve-2026-63772</guid>
      <pubDate>Fri, 02 Oct 2026 12:52:07 +0000</pubDate>
    </item>
    <item>
      <title>cve-2026-61374</title>
      <link>https://127.0.0.1:10001/vuln/cve-2026-61374</link>
      <description>Apache Thrift: Java TSaslTransport post-auth data-frame missing size limit</description>
      <content:encoded>Apache Thrift: Java TSaslTransport post-auth data-frame missing size limit</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/cve-2026-61374</guid>
      <pubDate>Fri, 02 Oct 2026 12:53:00 +0000</pubDate>
    </item>
    <item>
      <title>cve-2026-66054</title>
      <link>https://127.0.0.1:10001/vuln/cve-2026-66054</link>
      <description>Apache Thrift: C++ THeaderTransport does not enforce configured maxFrameSize</description>
      <content:encoded>Apache Thrift: C++ THeaderTransport does not enforce configured maxFrameSize</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/cve-2026-66054</guid>
      <pubDate>Fri, 02 Oct 2026 12:58:05 +0000</pubDate>
    </item>
    <item>
      <title>cve-2026-101104</title>
      <link>https://127.0.0.1:10001/vuln/cve-2026-101104</link>
      <description>Missing Authorization in Meari IoT Cloud Platform OpenAPI Service</description>
      <content:encoded>Missing Authorization in Meari IoT Cloud Platform OpenAPI Service</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/cve-2026-101104</guid>
      <pubDate>Fri, 02 Oct 2026 15:58:21 +0000</pubDate>
    </item>
    <item>
      <title>cve-2026-104910</title>
      <link>https://127.0.0.1:10001/vuln/cve-2026-104910</link>
      <description>MISP Information Disclosure via Related Events Listing Bypassing Per-Event Authorization</description>
      <content:encoded>MISP Information Disclosure via Related Events Listing Bypassing Per-Event Authorization</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/cve-2026-104910</guid>
      <pubDate>Fri, 02 Oct 2026 16:01:32 +0000</pubDate>
    </item>
    <item>
      <title>cve-2026-96613</title>
      <link>https://127.0.0.1:10001/vuln/cve-2026-96613</link>
      <description>Missing Authorization in Meari IoT Cloud Platform OpenAPI Service</description>
      <content:encoded>Missing Authorization in Meari IoT Cloud Platform OpenAPI Service</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/cve-2026-96613</guid>
      <pubDate>Fri, 02 Oct 2026 16:03:04 +0000</pubDate>
    </item>
    <item>
      <title>cve-2026-104912</title>
      <link>https://127.0.0.1:10001/vuln/cve-2026-104912</link>
      <description>MISP Correlation Authorization Bypass Exposes Restricted Event and Attribute Data</description>
      <content:encoded>MISP Correlation Authorization Bypass Exposes Restricted Event and Attribute Data</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/cve-2026-104912</guid>
      <pubDate>Fri, 02 Oct 2026 16:04:50 +0000</pubDate>
    </item>
    <item>
      <title>cve-2026-103648</title>
      <link>https://127.0.0.1:10001/vuln/cve-2026-103648</link>
      <description>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in image-downloader</description>
      <content:encoded>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in image-downloader</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/cve-2026-103648</guid>
      <pubDate>Fri, 02 Oct 2026 16:05:25 +0000</pubDate>
    </item>
  </channel>
</rss>
