RHSA-2026:74369

Vulnerability from csaf_redhat - Published: 2026-10-01 06:16 - Updated: 2026-10-02 22:10
Summary
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Severity
Important
Notes
Topic: An update for Red Hat Hardened Images RPMs is now available.
Details: This update includes the following RPMs: thrift: * perl-thrift-0.25.0-0.1.hum1 (noarch) * python3-thrift-0.25.0-0.1.hum1 (aarch64, x86_64) * thrift-0.25.0-0.1.hum1 (aarch64, x86_64) * thrift-devel-0.25.0-0.1.hum1 (aarch64, x86_64) * thrift-glib-0.25.0-0.1.hum1 (aarch64, x86_64) * thrift-qt-0.25.0-0.1.hum1 (aarch64, x86_64) * thrift-0.25.0-0.1.hum1.src (src)
Terms of Use: This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.

A flaw was found in the Apache Thrift C++ bindings. A remote, unauthenticated attacker could cause a Denial of Service (DoS) by sending specially crafted, highly compressed data payloads. Because the software does not properly restrict resource allocation during decompression, processing these payloads can exhaust system resources and render the service unavailable.

CWE-409 - Improper Handling of Highly Compressed Data (Data Amplification)
Affected products
Product Identifier Version Remediation
Unresolved product id: Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms —
Vendor Fix fix
Unresolved product id: Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms —
Vendor Fix fix
Unresolved product id: Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64 —
Vendor Fix fix
Unresolved product id: Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64 —
Vendor Fix fix
Unresolved product id: Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64 —
Vendor Fix fix
Unresolved product id: Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src —
Vendor Fix fix
Unresolved product id: Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64 —
Vendor Fix fix
Unresolved product id: Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64 —
Vendor Fix fix
Unresolved product id: Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64 —
Vendor Fix fix
Unresolved product id: Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64 —
Vendor Fix fix
Unresolved product id: Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64 —
Vendor Fix fix
Unresolved product id: Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64 —
Vendor Fix fix
Unresolved product id: Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64 —
Vendor Fix fix
Threats
Impact Important

A flaw was found in Apache Thrift's C GLib bindings. A remote, unauthenticated attacker could exploit this vulnerability by sending specially crafted input that triggers the access of an uninitialized pointer. This access can cause the application to crash, resulting in a Denial of Service (DoS).

CWE-824 - Access of Uninitialized Pointer
Affected products
Fixed 13 products, the same list as for CVE-2026-66054
Threats
Impact Important

A flaw was found in Apache Thrift's Delphi bindings buffered transport. The component fails to properly restrict or throttle resource allocation when processing input. A remote, unauthenticated attacker could exploit this vulnerability to consume excessive system resources, resulting in a Denial of Service (DoS).

CWE-770 - Allocation of Resources Without Limits or Throttling
Affected products
Fixed 13 products, the same list as for CVE-2026-66054
Threats
Impact Moderate

A flaw was found in Apache Thrift. An integer overflow within the PHP bindings leads to a stack-based buffer overflow when processing specially crafted data. A remote, unauthenticated attacker could exploit this flaw to crash the service, leading to a Denial of Service (DoS).

CWE-787 - Out-of-bounds Write
Affected products
Fixed 13 products, the same list as for CVE-2026-66054
Threats
Impact Important

A flaw was found in Apache Thrift. Multiple language bindings fail to enforce recursion limits when processing skipped fields in incoming messages. A remote, unauthenticated attacker can exploit this vulnerability by sending a message containing deeply nested unknown fields, leading to stack exhaustion and causing a Denial of Service (DoS) through an application crash.

CWE-770 - Allocation of Resources Without Limits or Throttling
Affected products
Fixed 13 products, the same list as for CVE-2026-66054
Threats
Impact Important

A flaw was found in Apache Thrift. Multiple language bindings fail to properly restrict memory allocation when processing input containing excessive size values. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted requests, consuming available memory and causing a Denial of Service (DoS).

CWE-770 - Allocation of Resources Without Limits or Throttling
Affected products
Fixed 13 products, the same list as for CVE-2026-66054
Threats
Impact Important

A flaw was found in Apache Thrift. A remote, unauthenticated attacker could cause a Denial of Service (DoS) by sending specially crafted network traffic to an affected application. Due to an integer underflow in the 32-bit C++ THeaderTransport component, processing this malformed data triggers an out-of-bounds memory write, leading to an application crash.

CWE-787 - Out-of-bounds Write
Affected products
Fixed 13 products, the same list as for CVE-2026-66054
Threats
Impact Important

A flaw was found in Apache Thrift. A remote attacker can cause a Denial of Service (DoS) against the Node.js and D WebSocket server transports by sending a frame specifying an excessively large payload length. Because the server immediately allocates the declared amount of memory without verifying that the payload data has arrived, an attacker can rapidly exhaust system memory and crash the service.

CWE-130 - Improper Handling of Length Parameter Inconsistency
Affected products
Fixed 13 products, the same list as for CVE-2026-66054
Threats
Impact Important

A flaw was found in Apache Thrift's Perl bindings. Due to insecure default settings and improper certificate validation, client connections fail to verify the authenticity of remote server certificates. An unauthenticated attacker positioned on the network could exploit this vulnerability to conduct a man-in-the-middle (MitM) attack, allowing them to eavesdrop on or alter transmitted data and resulting in information disclosure.

CWE-295 - Improper Certificate Validation
Affected products
Fixed 13 products, the same list as for CVE-2026-66054
Threats
Impact Important

A flaw was found in Apache Thrift. During Transport Layer Security (TLS) certificate validation, the client libraries improperly evaluate the certificate's Common Name (CN) when subject alternative name (SAN) entries do not match the target host. A network-positioned attacker possessing a trusted certificate matching the host's Common Name can exploit this vulnerability to impersonate the legitimate server. Successful exploitation allows the attacker to intercept or tamper with encrypted communications.

CWE-295 - Improper Certificate Validation
Affected products
Fixed 13 products, the same list as for CVE-2026-66054
Threats
Impact Important

A flaw was found in Apache Thrift. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending specially crafted requests to applications utilizing affected language bindings. Flawed input parameter processing and resource allocation can trigger application crashes or excessive resource consumption, rendering the service unavailable.

CWE-130 - Improper Handling of Length Parameter Inconsistency
Affected products
Fixed 13 products, the same list as for CVE-2026-66054
Threats
Impact Important

A flaw was found in Apache Thrift. A remote attacker can exploit this vulnerability by submitting specially crafted messages to applications using the Node.js bindings with TJSONProtocol. Successful exploitation can trigger an infinite loop or cause prototype pollution (unintended modification of shared object attributes), resulting in a Denial of Service (DoS).

CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')
Affected products
Fixed 13 products, the same list as for CVE-2026-66054
Threats
Impact Important

A flaw was found in Apache Thrift's D language bindings. A remote, unauthenticated attacker could cause a Denial of Service (DoS) by sending specially crafted input to an affected application. This input triggers an integer underflow or an unhandled exception, causing the process to enter an infinite loop or terminate unexpectedly.

CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')
Affected products
Fixed 13 products, the same list as for CVE-2026-66054
Threats
Impact Important

A flaw was found in Apache Thrift's D language implementation within the TNonblockingServer component. Due to improper handling of exceptional conditions and improper resource shutdown, an uncaught exception can occur during server operations. A remote, unauthenticated attacker could exploit this vulnerability to cause a Denial of Service (DoS) by terminating the server process.

CWE-248 - Uncaught Exception
Affected products
Fixed 13 products, the same list as for CVE-2026-66054
Threats
Impact Important

A flaw was found in Apache Thrift. An incorrect bitwise integer shift in the C++ THeaderProtocol implementation can cause a stack-based buffer overflow. A remote, unauthenticated attacker could exploit this vulnerability by sending specially crafted input, resulting in a Denial of Service (DoS) caused by an application crash.

CWE-787 - Out-of-bounds Write
Affected products
Fixed 13 products, the same list as for CVE-2026-66054
Threats
Impact Important

A flaw was found in Apache Thrift's THeaderTransport component. Due to a failure to release allocated memory and system resources after their operational lifetime, a remote attacker can exploit this vulnerability by sending network traffic that repeatedly consumes resources. This issue can cause system memory exhaustion, leading to a Denial of Service (DoS).

CWE-772 - Missing Release of Resource after Effective Lifetime
Affected products
Fixed 13 products, the same list as for CVE-2026-66054
Threats
Impact Important

A flaw was found in Apache Thrift's Dart bindings. An unauthenticated remote attacker can exploit this vulnerability by sending input containing inconsistent length parameters, triggering excessive memory allocation. This can lead to system memory exhaustion, resulting in a Denial of Service (DoS) condition.

CWE-770 - Allocation of Resources Without Limits or Throttling
Affected products
Fixed 13 products, the same list as for CVE-2026-66054
Threats
Impact Important

A flaw was found in the Apache Thrift Lua bindings. A remote attacker could exploit this vulnerability by sending requests containing inconsistent length parameters, triggering excessive resource allocation without proper limits. This issue can exhaust available system memory or processing capacity, resulting in a Denial of Service (DoS).

CWE-130 - Improper Handling of Length Parameter Inconsistency
Affected products
Fixed 13 products, the same list as for CVE-2026-66054
Threats
Impact Important

A flaw was found in the Apache Thrift PHP bindings. Due to a lack of limits or throttling on resource allocation, a remote attacker can send crafted requests that consume excessive system resources. This issue can lead to a Denial of Service (DoS) for the affected service.

CWE-770 - Allocation of Resources Without Limits or Throttling
Affected products
Fixed 13 products, the same list as for CVE-2026-66054
Threats
Impact Moderate

A flaw was found in Apache Thrift's Node.js bindings. Due to improper input validation and prototype pollution—a condition where base JavaScript object properties can be modified—the application fails to safely process incoming data. A remote attacker can exploit this vulnerability by sending specially crafted input to trigger an uncaught exception, causing the service to crash and resulting in a Denial of Service (DoS).

CWE-915 - Improperly Controlled Modification of Dynamically-Determined Object Attributes
Affected products
Fixed 13 products, the same list as for CVE-2026-66054
Threats
Impact Important

A flaw was found in Apache Thrift. An uncontrolled recursion vulnerability in the C (GLib) library bindings allows a remote, unauthenticated attacker to send specially crafted input to an affected application. Processing this input triggers excessive nested function calls that exhaust stack memory, causing an application crash and resulting in a Denial of Service (DoS).

CWE-770 - Allocation of Resources Without Limits or Throttling
Affected products
Fixed 13 products, the same list as for CVE-2026-66054
Threats
Impact Important

A flaw was found in Apache Thrift. A remote attacker could exploit improper resource allocation controls in the JavaME bindings to cause a Denial of Service (DoS). By sending requests that trigger unbounded resource consumption, an attacker can exhaust system resources and make the service unavailable.

CWE-770 - Allocation of Resources Without Limits or Throttling
Affected products
Fixed 13 products, the same list as for CVE-2026-66054
Threats
Impact Important

A flaw was found in the Apache Thrift Ruby bindings. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) due to improper handling of exceptional conditions. By triggering an uncaught exception, an attacker can crash the service and disrupt availability.

CWE-248 - Uncaught Exception
Affected products
Fixed 13 products, the same list as for CVE-2026-66054
Threats
Impact Important

A flaw was found in Apache Thrift's Lua bindings. A remote attacker could exploit this vulnerability by sending specially crafted input that triggers inefficient regular expression processing. This can cause excessive resource consumption, resulting in a Denial of Service (DoS) on the affected service.

CWE-1333 - Inefficient Regular Expression Complexity
Affected products
Fixed 13 products, the same list as for CVE-2026-66054
Threats
Impact Important
References
URL Category
https://access.redhat.com/errata/RHSA-2026:74369 self
https://images.redhat.com/ external
https://access.redhat.com/security/cve/CVE-2026-94635 external
https://access.redhat.com/security/updates/classi… external
https://access.redhat.com/security/cve/CVE-2026-93926 external
https://access.redhat.com/security/cve/CVE-2026-94634 external
https://access.redhat.com/security/cve/CVE-2026-93925 external
https://access.redhat.com/security/cve/CVE-2026-94633 external
https://access.redhat.com/security/cve/CVE-2026-85483 external
https://access.redhat.com/security/cve/CVE-2026-85494 external
https://access.redhat.com/security/cve/CVE-2026-91137 external
https://access.redhat.com/security/cve/CVE-2026-85087 external
https://access.redhat.com/security/cve/CVE-2026-87117 external
https://access.redhat.com/security/cve/CVE-2026-90440 external
https://access.redhat.com/security/cve/CVE-2026-94650 external
https://access.redhat.com/security/cve/CVE-2026-96294 external
https://access.redhat.com/security/cve/CVE-2026-94644 external
https://access.redhat.com/security/cve/CVE-2026-85086 external
https://access.redhat.com/security/cve/CVE-2026-82458 external
https://access.redhat.com/security/cve/CVE-2026-96990 external
https://access.redhat.com/security/cve/CVE-2026-94645 external
https://access.redhat.com/security/cve/CVE-2026-82459 external
https://access.redhat.com/security/cve/CVE-2026-85493 external
https://access.redhat.com/security/cve/CVE-2026-96292 external
https://access.redhat.com/security/cve/CVE-2026-96288 external
https://access.redhat.com/security/cve/CVE-2026-66331 external
https://access.redhat.com/security/cve/CVE-2026-83745 external
https://access.redhat.com/security/cve/CVE-2026-94638 external
https://access.redhat.com/security/cve/CVE-2026-94654 external
https://access.redhat.com/security/cve/CVE-2026-94657 external
https://access.redhat.com/security/cve/CVE-2026-96277 external
https://access.redhat.com/security/cve/CVE-2026-86535 external
https://access.redhat.com/security/cve/CVE-2026-92834 external
https://access.redhat.com/security/cve/CVE-2026-94652 external
https://access.redhat.com/security/cve/CVE-2026-85088 external
https://access.redhat.com/security/cve/CVE-2026-86536 external
https://access.redhat.com/security/cve/CVE-2026-94658 external
https://access.redhat.com/security/cve/CVE-2026-66837 external
https://access.redhat.com/security/cve/CVE-2026-96289 external
https://access.redhat.com/security/cve/CVE-2026-66859 external
https://access.redhat.com/security/cve/CVE-2026-94646 external
https://access.redhat.com/security/cve/CVE-2026-96287 external
https://access.redhat.com/security/cve/CVE-2026-96286 external
https://access.redhat.com/security/cve/CVE-2026-85476 external
https://access.redhat.com/security/cve/CVE-2026-66054 external
https://access.redhat.com/security/cve/CVE-2026-94636 external
https://access.redhat.com/security/cve/CVE-2026-94656 external
https://access.redhat.com/security/cve/CVE-2026-66858 external
https://access.redhat.com/security/cve/CVE-2026-66081 external
https://access.redhat.com/security/cve/CVE-2026-94655 external
https://access.redhat.com/security/cve/CVE-2026-66055 external
https://access.redhat.com/security/cve/CVE-2026-94648 external
https://access.redhat.com/security/cve/CVE-2026-94653 external
https://access.redhat.com/security/cve/CVE-2026-86537 external
https://security.access.redhat.com/data/csaf/v2/a… self
https://access.redhat.com/security/cve/CVE-2026-66054 self
https://bugzilla.redhat.com/show_bug.cgi?id=2545180 external
https://www.cve.org/CVERecord?id=CVE-2026-66054 external
https://nvd.nist.gov/vuln/detail/CVE-2026-66054 external
https://lists.apache.org/thread/33otcgbqd27wf6qq8… external
https://lists.apache.org/thread/7c23sgowkb3ssmolq… external
https://access.redhat.com/security/cve/CVE-2026-66081 self
https://bugzilla.redhat.com/show_bug.cgi?id=2545165 external
https://www.cve.org/CVERecord?id=CVE-2026-66081 external
https://nvd.nist.gov/vuln/detail/CVE-2026-66081 external
https://lists.apache.org/thread/9d51ygo6hrsdo5ndw… external
https://access.redhat.com/security/cve/CVE-2026-66331 self
https://bugzilla.redhat.com/show_bug.cgi?id=2545175 external
https://www.cve.org/CVERecord?id=CVE-2026-66331 external
https://nvd.nist.gov/vuln/detail/CVE-2026-66331 external
https://lists.apache.org/thread/971572orz86jdwlg5… external
https://access.redhat.com/security/cve/CVE-2026-66837 self
https://bugzilla.redhat.com/show_bug.cgi?id=2545163 external
https://www.cve.org/CVERecord?id=CVE-2026-66837 external
https://nvd.nist.gov/vuln/detail/CVE-2026-66837 external
https://lists.apache.org/thread/7o985t84551tpo55v… external
https://access.redhat.com/security/cve/CVE-2026-66858 self
https://bugzilla.redhat.com/show_bug.cgi?id=2545169 external
https://www.cve.org/CVERecord?id=CVE-2026-66858 external
https://nvd.nist.gov/vuln/detail/CVE-2026-66858 external
https://lists.apache.org/thread/6kl6g40tpl8zt3opd… external
https://access.redhat.com/security/cve/CVE-2026-82458 self
https://bugzilla.redhat.com/show_bug.cgi?id=2545042 external
https://www.cve.org/CVERecord?id=CVE-2026-82458 external
https://nvd.nist.gov/vuln/detail/CVE-2026-82458 external
https://lists.apache.org/thread/7xqf651pvjykw0xr9… external
https://access.redhat.com/security/cve/CVE-2026-82459 self
https://bugzilla.redhat.com/show_bug.cgi?id=2545041 external
https://www.cve.org/CVERecord?id=CVE-2026-82459 external
https://nvd.nist.gov/vuln/detail/CVE-2026-82459 external
https://lists.apache.org/thread/zf8ppfpl6nqhp53sx… external
https://access.redhat.com/security/cve/CVE-2026-83745 self
https://bugzilla.redhat.com/show_bug.cgi?id=2545142 external
https://www.cve.org/CVERecord?id=CVE-2026-83745 external
https://nvd.nist.gov/vuln/detail/CVE-2026-83745 external
https://lists.apache.org/thread/64y7f0b89mnq4xoqc… external
https://access.redhat.com/security/cve/CVE-2026-85086 self
https://bugzilla.redhat.com/show_bug.cgi?id=2545053 external
https://www.cve.org/CVERecord?id=CVE-2026-85086 external
https://nvd.nist.gov/vuln/detail/CVE-2026-85086 external
https://lists.apache.org/thread/c7f9g4027ok0gocys… external
https://access.redhat.com/security/cve/CVE-2026-85088 self
https://bugzilla.redhat.com/show_bug.cgi?id=2545088 external
https://www.cve.org/CVERecord?id=CVE-2026-85088 external
https://nvd.nist.gov/vuln/detail/CVE-2026-85088 external
https://lists.apache.org/thread/zcgm7lx6037lvgvn8… external
https://access.redhat.com/security/cve/CVE-2026-85494 self
https://bugzilla.redhat.com/show_bug.cgi?id=2545019 external
https://www.cve.org/CVERecord?id=CVE-2026-85494 external
https://nvd.nist.gov/vuln/detail/CVE-2026-85494 external
https://lists.apache.org/thread/rm0m34gt6fh1flvt1… external
https://access.redhat.com/security/cve/CVE-2026-86535 self
https://bugzilla.redhat.com/show_bug.cgi?id=2545128 external
https://www.cve.org/CVERecord?id=CVE-2026-86535 external
https://nvd.nist.gov/vuln/detail/CVE-2026-86535 external
https://lists.apache.org/thread/94cvvzzl0rh707bn2… external
https://access.redhat.com/security/cve/CVE-2026-86537 self
https://bugzilla.redhat.com/show_bug.cgi?id=2545121 external
https://www.cve.org/CVERecord?id=CVE-2026-86537 external
https://nvd.nist.gov/vuln/detail/CVE-2026-86537 external
https://lists.apache.org/thread/k14jfr1xwc0vtmm2s… external
https://access.redhat.com/security/cve/CVE-2026-90440 self
https://bugzilla.redhat.com/show_bug.cgi?id=2545066 external
https://www.cve.org/CVERecord?id=CVE-2026-90440 external
https://nvd.nist.gov/vuln/detail/CVE-2026-90440 external
https://lists.apache.org/thread/s8fjltl6c1pkm7vg9… external
https://access.redhat.com/security/cve/CVE-2026-93925 self
https://bugzilla.redhat.com/show_bug.cgi?id=2545010 external
https://www.cve.org/CVERecord?id=CVE-2026-93925 external
https://nvd.nist.gov/vuln/detail/CVE-2026-93925 external
https://lists.apache.org/thread/b4rrkrwoyqb9g7hk5… external
https://access.redhat.com/security/cve/CVE-2026-93926 self
https://bugzilla.redhat.com/show_bug.cgi?id=2545008 external
https://www.cve.org/CVERecord?id=CVE-2026-93926 external
https://nvd.nist.gov/vuln/detail/CVE-2026-93926 external
https://lists.apache.org/thread/9353rb8mpoq4ltff8… external
https://access.redhat.com/security/cve/CVE-2026-94633 self
https://bugzilla.redhat.com/show_bug.cgi?id=2545011 external
https://www.cve.org/CVERecord?id=CVE-2026-94633 external
https://nvd.nist.gov/vuln/detail/CVE-2026-94633 external
https://lists.apache.org/thread/cxkbblyht7988p2o6… external
https://access.redhat.com/security/cve/CVE-2026-94635 self
https://bugzilla.redhat.com/show_bug.cgi?id=2544989 external
https://www.cve.org/CVERecord?id=CVE-2026-94635 external
https://nvd.nist.gov/vuln/detail/CVE-2026-94635 external
https://lists.apache.org/thread/ow8994gb5g8ssmmbk… external
https://access.redhat.com/security/cve/CVE-2026-94638 self
https://bugzilla.redhat.com/show_bug.cgi?id=2545160 external
https://www.cve.org/CVERecord?id=CVE-2026-94638 external
https://nvd.nist.gov/vuln/detail/CVE-2026-94638 external
https://lists.apache.org/thread/v60w786pqr7njzz94… external
https://access.redhat.com/security/cve/CVE-2026-94646 self
https://bugzilla.redhat.com/show_bug.cgi?id=2545138 external
https://www.cve.org/CVERecord?id=CVE-2026-94646 external
https://nvd.nist.gov/vuln/detail/CVE-2026-94646 external
https://lists.apache.org/thread/5hjh0gz8wf6bo7ydx… external
https://access.redhat.com/security/cve/CVE-2026-94650 self
https://bugzilla.redhat.com/show_bug.cgi?id=2545020 external
https://www.cve.org/CVERecord?id=CVE-2026-94650 external
https://nvd.nist.gov/vuln/detail/CVE-2026-94650 external
https://lists.apache.org/thread/poskkt3p754b2f293… external
https://access.redhat.com/security/cve/CVE-2026-94657 self
https://bugzilla.redhat.com/show_bug.cgi?id=2545148 external
https://www.cve.org/CVERecord?id=CVE-2026-94657 external
https://nvd.nist.gov/vuln/detail/CVE-2026-94657 external
https://lists.apache.org/thread/lpcmo2xjfyfww474x… external
https://access.redhat.com/security/cve/CVE-2026-96277 self
https://bugzilla.redhat.com/show_bug.cgi?id=2545159 external
https://www.cve.org/CVERecord?id=CVE-2026-96277 external
https://nvd.nist.gov/vuln/detail/CVE-2026-96277 external
https://lists.apache.org/thread/k1t5r9sz7k5tn57cn… external
https://access.redhat.com/security/cve/CVE-2026-96292 self
https://bugzilla.redhat.com/show_bug.cgi?id=2545035 external
https://www.cve.org/CVERecord?id=CVE-2026-96292 external
https://nvd.nist.gov/vuln/detail/CVE-2026-96292 external
https://lists.apache.org/thread/3wmvtvv56rky5wtsz… external

{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright \u00a9 Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "summary",
        "text": "An update for Red Hat Hardened Images RPMs is now available.",
        "title": "Topic"
      },
      {
        "category": "general",
        "text": "This update includes the following RPMs:\n\nthrift:\n  * perl-thrift-0.25.0-0.1.hum1 (noarch)\n  * python3-thrift-0.25.0-0.1.hum1 (aarch64, x86_64)\n  * thrift-0.25.0-0.1.hum1 (aarch64, x86_64)\n  * thrift-devel-0.25.0-0.1.hum1 (aarch64, x86_64)\n  * thrift-glib-0.25.0-0.1.hum1 (aarch64, x86_64)\n  * thrift-qt-0.25.0-0.1.hum1 (aarch64, x86_64)\n  * thrift-0.25.0-0.1.hum1.src (src)",
        "title": "Details"
      },
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://access.redhat.com/errata/RHSA-2026:74369",
        "url": "https://access.redhat.com/errata/RHSA-2026:74369"
      },
      {
        "category": "external",
        "summary": "https://images.redhat.com/",
        "url": "https://images.redhat.com/"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-94635",
        "url": "https://access.redhat.com/security/cve/CVE-2026-94635"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/updates/classification/",
        "url": "https://access.redhat.com/security/updates/classification/"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-93926",
        "url": "https://access.redhat.com/security/cve/CVE-2026-93926"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-94634",
        "url": "https://access.redhat.com/security/cve/CVE-2026-94634"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-93925",
        "url": "https://access.redhat.com/security/cve/CVE-2026-93925"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-94633",
        "url": "https://access.redhat.com/security/cve/CVE-2026-94633"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-85483",
        "url": "https://access.redhat.com/security/cve/CVE-2026-85483"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-85494",
        "url": "https://access.redhat.com/security/cve/CVE-2026-85494"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-91137",
        "url": "https://access.redhat.com/security/cve/CVE-2026-91137"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-85087",
        "url": "https://access.redhat.com/security/cve/CVE-2026-85087"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-87117",
        "url": "https://access.redhat.com/security/cve/CVE-2026-87117"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-90440",
        "url": "https://access.redhat.com/security/cve/CVE-2026-90440"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-94650",
        "url": "https://access.redhat.com/security/cve/CVE-2026-94650"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-96294",
        "url": "https://access.redhat.com/security/cve/CVE-2026-96294"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-94644",
        "url": "https://access.redhat.com/security/cve/CVE-2026-94644"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-85086",
        "url": "https://access.redhat.com/security/cve/CVE-2026-85086"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-82458",
        "url": "https://access.redhat.com/security/cve/CVE-2026-82458"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-96990",
        "url": "https://access.redhat.com/security/cve/CVE-2026-96990"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-94645",
        "url": "https://access.redhat.com/security/cve/CVE-2026-94645"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-82459",
        "url": "https://access.redhat.com/security/cve/CVE-2026-82459"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-85493",
        "url": "https://access.redhat.com/security/cve/CVE-2026-85493"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-96292",
        "url": "https://access.redhat.com/security/cve/CVE-2026-96292"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-96288",
        "url": "https://access.redhat.com/security/cve/CVE-2026-96288"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-66331",
        "url": "https://access.redhat.com/security/cve/CVE-2026-66331"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-83745",
        "url": "https://access.redhat.com/security/cve/CVE-2026-83745"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-94638",
        "url": "https://access.redhat.com/security/cve/CVE-2026-94638"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-94654",
        "url": "https://access.redhat.com/security/cve/CVE-2026-94654"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-94657",
        "url": "https://access.redhat.com/security/cve/CVE-2026-94657"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-96277",
        "url": "https://access.redhat.com/security/cve/CVE-2026-96277"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-86535",
        "url": "https://access.redhat.com/security/cve/CVE-2026-86535"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-92834",
        "url": "https://access.redhat.com/security/cve/CVE-2026-92834"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-94652",
        "url": "https://access.redhat.com/security/cve/CVE-2026-94652"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-85088",
        "url": "https://access.redhat.com/security/cve/CVE-2026-85088"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-86536",
        "url": "https://access.redhat.com/security/cve/CVE-2026-86536"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-94658",
        "url": "https://access.redhat.com/security/cve/CVE-2026-94658"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-66837",
        "url": "https://access.redhat.com/security/cve/CVE-2026-66837"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-96289",
        "url": "https://access.redhat.com/security/cve/CVE-2026-96289"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-66859",
        "url": "https://access.redhat.com/security/cve/CVE-2026-66859"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-94646",
        "url": "https://access.redhat.com/security/cve/CVE-2026-94646"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-96287",
        "url": "https://access.redhat.com/security/cve/CVE-2026-96287"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-96286",
        "url": "https://access.redhat.com/security/cve/CVE-2026-96286"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-85476",
        "url": "https://access.redhat.com/security/cve/CVE-2026-85476"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-66054",
        "url": "https://access.redhat.com/security/cve/CVE-2026-66054"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-94636",
        "url": "https://access.redhat.com/security/cve/CVE-2026-94636"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-94656",
        "url": "https://access.redhat.com/security/cve/CVE-2026-94656"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-66858",
        "url": "https://access.redhat.com/security/cve/CVE-2026-66858"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-66081",
        "url": "https://access.redhat.com/security/cve/CVE-2026-66081"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-94655",
        "url": "https://access.redhat.com/security/cve/CVE-2026-94655"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-66055",
        "url": "https://access.redhat.com/security/cve/CVE-2026-66055"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-94648",
        "url": "https://access.redhat.com/security/cve/CVE-2026-94648"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-94653",
        "url": "https://access.redhat.com/security/cve/CVE-2026-94653"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-86537",
        "url": "https://access.redhat.com/security/cve/CVE-2026-86537"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_74369.json"
      }
    ],
    "title": "Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update",
    "tracking": {
      "current_release_date": "2026-10-02T22:10:24+00:00",
      "generator": {
        "date": "2026-10-02T22:10:24+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "5.4.0"
        }
      },
      "id": "RHSA-2026:74369",
      "initial_release_date": "2026-10-01T06:16:09+00:00",
      "revision_history": [
        {
          "date": "2026-10-01T06:16:09+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-10-02T16:32:28+00:00",
          "number": "2",
          "summary": "Last updated version"
        },
        {
          "date": "2026-10-02T22:10:24+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Hardened Images",
                "product": {
                  "name": "Red Hat Hardened Images",
                  "product_id": "Red Hat Hardened Images",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:hummingbird:1"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Hardened Images"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
                "product": {
                  "name": "perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
                  "product_id": "perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/perl-thrift@0.25.0-0.1.hum1?arch=noarch\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-aarch64-rpms"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
                "product": {
                  "name": "perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
                  "product_id": "perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/perl-thrift@0.25.0-0.1.hum1?arch=noarch\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-x86_64-rpms"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "noarch"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "python3-thrift-0:0.25.0-0.1.hum1@aarch64",
                "product": {
                  "name": "python3-thrift-0:0.25.0-0.1.hum1@aarch64",
                  "product_id": "python3-thrift-0:0.25.0-0.1.hum1@aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/python3-thrift@0.25.0-0.1.hum1?arch=aarch64\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-aarch64-rpms"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "thrift-0:0.25.0-0.1.hum1@aarch64",
                "product": {
                  "name": "thrift-0:0.25.0-0.1.hum1@aarch64",
                  "product_id": "thrift-0:0.25.0-0.1.hum1@aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/thrift@0.25.0-0.1.hum1?arch=aarch64\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-aarch64-rpms"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "thrift-devel-0:0.25.0-0.1.hum1@aarch64",
                "product": {
                  "name": "thrift-devel-0:0.25.0-0.1.hum1@aarch64",
                  "product_id": "thrift-devel-0:0.25.0-0.1.hum1@aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/thrift-devel@0.25.0-0.1.hum1?arch=aarch64\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-aarch64-rpms"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "thrift-glib-0:0.25.0-0.1.hum1@aarch64",
                "product": {
                  "name": "thrift-glib-0:0.25.0-0.1.hum1@aarch64",
                  "product_id": "thrift-glib-0:0.25.0-0.1.hum1@aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/thrift-glib@0.25.0-0.1.hum1?arch=aarch64\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-aarch64-rpms"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "thrift-qt-0:0.25.0-0.1.hum1@aarch64",
                "product": {
                  "name": "thrift-qt-0:0.25.0-0.1.hum1@aarch64",
                  "product_id": "thrift-qt-0:0.25.0-0.1.hum1@aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/thrift-qt@0.25.0-0.1.hum1?arch=aarch64\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-aarch64-rpms"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "aarch64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "python3-thrift-0:0.25.0-0.1.hum1@x86_64",
                "product": {
                  "name": "python3-thrift-0:0.25.0-0.1.hum1@x86_64",
                  "product_id": "python3-thrift-0:0.25.0-0.1.hum1@x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/python3-thrift@0.25.0-0.1.hum1?arch=x86_64\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-x86_64-rpms"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "thrift-0:0.25.0-0.1.hum1@x86_64",
                "product": {
                  "name": "thrift-0:0.25.0-0.1.hum1@x86_64",
                  "product_id": "thrift-0:0.25.0-0.1.hum1@x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/thrift@0.25.0-0.1.hum1?arch=x86_64\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-x86_64-rpms"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "thrift-devel-0:0.25.0-0.1.hum1@x86_64",
                "product": {
                  "name": "thrift-devel-0:0.25.0-0.1.hum1@x86_64",
                  "product_id": "thrift-devel-0:0.25.0-0.1.hum1@x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/thrift-devel@0.25.0-0.1.hum1?arch=x86_64\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-x86_64-rpms"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "thrift-glib-0:0.25.0-0.1.hum1@x86_64",
                "product": {
                  "name": "thrift-glib-0:0.25.0-0.1.hum1@x86_64",
                  "product_id": "thrift-glib-0:0.25.0-0.1.hum1@x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/thrift-glib@0.25.0-0.1.hum1?arch=x86_64\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-x86_64-rpms"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "thrift-qt-0:0.25.0-0.1.hum1@x86_64",
                "product": {
                  "name": "thrift-qt-0:0.25.0-0.1.hum1@x86_64",
                  "product_id": "thrift-qt-0:0.25.0-0.1.hum1@x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/thrift-qt@0.25.0-0.1.hum1?arch=x86_64\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-x86_64-rpms"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "thrift-0:0.25.0-0.1.hum1@src",
                "product": {
                  "name": "thrift-0:0.25.0-0.1.hum1@src",
                  "product_id": "thrift-0:0.25.0-0.1.hum1@src",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/thrift@0.25.0-0.1.hum1?arch=src\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-source-rpms"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "src"
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms as a component of Red Hat Hardened Images",
          "product_id": "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms"
        },
        "product_reference": "perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
        "relates_to_product_reference": "Red Hat Hardened Images"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms as a component of Red Hat Hardened Images",
          "product_id": "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms"
        },
        "product_reference": "perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
        "relates_to_product_reference": "Red Hat Hardened Images"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "python3-thrift-0:0.25.0-0.1.hum1@aarch64 as a component of Red Hat Hardened Images",
          "product_id": "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64"
        },
        "product_reference": "python3-thrift-0:0.25.0-0.1.hum1@aarch64",
        "relates_to_product_reference": "Red Hat Hardened Images"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "python3-thrift-0:0.25.0-0.1.hum1@x86_64 as a component of Red Hat Hardened Images",
          "product_id": "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64"
        },
        "product_reference": "python3-thrift-0:0.25.0-0.1.hum1@x86_64",
        "relates_to_product_reference": "Red Hat Hardened Images"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "thrift-0:0.25.0-0.1.hum1@aarch64 as a component of Red Hat Hardened Images",
          "product_id": "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64"
        },
        "product_reference": "thrift-0:0.25.0-0.1.hum1@aarch64",
        "relates_to_product_reference": "Red Hat Hardened Images"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "thrift-0:0.25.0-0.1.hum1@src as a component of Red Hat Hardened Images",
          "product_id": "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src"
        },
        "product_reference": "thrift-0:0.25.0-0.1.hum1@src",
        "relates_to_product_reference": "Red Hat Hardened Images"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "thrift-0:0.25.0-0.1.hum1@x86_64 as a component of Red Hat Hardened Images",
          "product_id": "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64"
        },
        "product_reference": "thrift-0:0.25.0-0.1.hum1@x86_64",
        "relates_to_product_reference": "Red Hat Hardened Images"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "thrift-devel-0:0.25.0-0.1.hum1@aarch64 as a component of Red Hat Hardened Images",
          "product_id": "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64"
        },
        "product_reference": "thrift-devel-0:0.25.0-0.1.hum1@aarch64",
        "relates_to_product_reference": "Red Hat Hardened Images"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "thrift-devel-0:0.25.0-0.1.hum1@x86_64 as a component of Red Hat Hardened Images",
          "product_id": "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64"
        },
        "product_reference": "thrift-devel-0:0.25.0-0.1.hum1@x86_64",
        "relates_to_product_reference": "Red Hat Hardened Images"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "thrift-glib-0:0.25.0-0.1.hum1@aarch64 as a component of Red Hat Hardened Images",
          "product_id": "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64"
        },
        "product_reference": "thrift-glib-0:0.25.0-0.1.hum1@aarch64",
        "relates_to_product_reference": "Red Hat Hardened Images"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "thrift-glib-0:0.25.0-0.1.hum1@x86_64 as a component of Red Hat Hardened Images",
          "product_id": "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64"
        },
        "product_reference": "thrift-glib-0:0.25.0-0.1.hum1@x86_64",
        "relates_to_product_reference": "Red Hat Hardened Images"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "thrift-qt-0:0.25.0-0.1.hum1@aarch64 as a component of Red Hat Hardened Images",
          "product_id": "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64"
        },
        "product_reference": "thrift-qt-0:0.25.0-0.1.hum1@aarch64",
        "relates_to_product_reference": "Red Hat Hardened Images"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "thrift-qt-0:0.25.0-0.1.hum1@x86_64 as a component of Red Hat Hardened Images",
          "product_id": "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
        },
        "product_reference": "thrift-qt-0:0.25.0-0.1.hum1@x86_64",
        "relates_to_product_reference": "Red Hat Hardened Images"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-66054",
      "cwe": {
        "id": "CWE-409",
        "name": "Improper Handling of Highly Compressed Data (Data Amplification)"
      },
      "discovery_date": "2026-10-02T13:14:14.506786+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2545180"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in the Apache Thrift C++ bindings. A remote, unauthenticated attacker could cause a Denial of Service (DoS) by sending specially crafted, highly compressed data payloads. Because the software does not properly restrict resource allocation during decompression, processing these payloads can exhaust system resources and render the service unavailable.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "thrift: thrift: Denial of Service via improper handling of compressed data",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-66054"
        },
        {
          "category": "external",
          "summary": "RHBZ#2545180",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545180"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-66054",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-66054"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-66054",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66054"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
          "url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/7c23sgowkb3ssmolqofqsn8wzsddvf33",
          "url": "https://lists.apache.org/thread/7c23sgowkb3ssmolqofqsn8wzsddvf33"
        }
      ],
      "release_date": "2026-10-02T12:58:05.610000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-01T06:16:09+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74369"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ],
      "title": "thrift: thrift: Denial of Service via improper handling of compressed data"
    },
    {
      "cve": "CVE-2026-66081",
      "cwe": {
        "id": "CWE-824",
        "name": "Access of Uninitialized Pointer"
      },
      "discovery_date": "2026-10-02T12:54:48.102391+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2545165"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Apache Thrift\u0027s C GLib bindings. A remote, unauthenticated attacker could exploit this vulnerability by sending specially crafted input that triggers the access of an uninitialized pointer. This access can cause the application to crash, resulting in a Denial of Service (DoS).",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "thrift: thrift: Denial of Service via uninitialized pointer access in c_glib bindings",
          "title": "Vulnerability summary"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-66081"
        },
        {
          "category": "external",
          "summary": "RHBZ#2545165",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545165"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-66081",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-66081"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-66081",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66081"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
          "url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/9d51ygo6hrsdo5ndwckbwt3mnp290m57",
          "url": "https://lists.apache.org/thread/9d51ygo6hrsdo5ndwckbwt3mnp290m57"
        }
      ],
      "release_date": "2026-10-02T12:33:13.645000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-01T06:16:09+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74369"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ],
      "title": "thrift: thrift: Denial of Service via uninitialized pointer access in c_glib bindings"
    },
    {
      "cve": "CVE-2026-66331",
      "cwe": {
        "id": "CWE-770",
        "name": "Allocation of Resources Without Limits or Throttling"
      },
      "discovery_date": "2026-10-02T13:00:06.119575+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2545175"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Apache Thrift\u0027s Delphi bindings buffered transport. The component fails to properly restrict or throttle resource allocation when processing input. A remote, unauthenticated attacker could exploit this vulnerability to consume excessive system resources, resulting in a Denial of Service (DoS).",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "thrift: thrift: Denial of Service via excessive resource allocation in Delphi buffered transport",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-66331"
        },
        {
          "category": "external",
          "summary": "RHBZ#2545175",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545175"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-66331",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-66331"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-66331",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66331"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
          "url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/971572orz86jdwlg58wqv8o50oqqb143",
          "url": "https://lists.apache.org/thread/971572orz86jdwlg58wqv8o50oqqb143"
        }
      ],
      "release_date": "2026-10-02T12:32:46.166000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-01T06:16:09+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74369"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ],
      "title": "thrift: thrift: Denial of Service via excessive resource allocation in Delphi buffered transport"
    },
    {
      "cve": "CVE-2026-66837",
      "cwe": {
        "id": "CWE-787",
        "name": "Out-of-bounds Write"
      },
      "discovery_date": "2026-10-02T12:53:32.129609+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2545163"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Apache Thrift. An integer overflow within the PHP bindings leads to a stack-based buffer overflow when processing specially crafted data. A remote, unauthenticated attacker could exploit this flaw to crash the service, leading to a Denial of Service (DoS).",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "thrift: thrift: Denial of Service via buffer overflow in PHP bindings",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-66837"
        },
        {
          "category": "external",
          "summary": "RHBZ#2545163",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545163"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-66837",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-66837"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-66837",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66837"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
          "url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/7o985t84551tpo55v6fsd3g42gs3zps1",
          "url": "https://lists.apache.org/thread/7o985t84551tpo55v6fsd3g42gs3zps1"
        }
      ],
      "release_date": "2026-10-02T12:29:09.189000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-01T06:16:09+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74369"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ],
      "title": "thrift: thrift: Denial of Service via buffer overflow in PHP bindings"
    },
    {
      "cve": "CVE-2026-66858",
      "cwe": {
        "id": "CWE-770",
        "name": "Allocation of Resources Without Limits or Throttling"
      },
      "discovery_date": "2026-10-02T12:56:52.055546+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2545169"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Apache Thrift. Multiple language bindings fail to enforce recursion limits when processing skipped fields in incoming messages. A remote, unauthenticated attacker can exploit this vulnerability by sending a message containing deeply nested unknown fields, leading to stack exhaustion and causing a Denial of Service (DoS) through an application crash.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "thrift: Apache Thrift: Denial of Service via deeply nested unknown fields",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-66858"
        },
        {
          "category": "external",
          "summary": "RHBZ#2545169",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545169"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-66858",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-66858"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-66858",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66858"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
          "url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/6kl6g40tpl8zt3opd8fwn6bsgyddzhd5",
          "url": "https://lists.apache.org/thread/6kl6g40tpl8zt3opd8fwn6bsgyddzhd5"
        }
      ],
      "release_date": "2026-10-02T12:27:31.412000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-01T06:16:09+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74369"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ],
      "title": "thrift: Apache Thrift: Denial of Service via deeply nested unknown fields"
    },
    {
      "cve": "CVE-2026-82458",
      "cwe": {
        "id": "CWE-770",
        "name": "Allocation of Resources Without Limits or Throttling"
      },
      "discovery_date": "2026-10-02T11:41:23.724436+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2545042"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Apache Thrift. Multiple language bindings fail to properly restrict memory allocation when processing input containing excessive size values. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted requests, consuming available memory and causing a Denial of Service (DoS).",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "thrift: thrift: Denial of Service via excessive memory allocation",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-82458"
        },
        {
          "category": "external",
          "summary": "RHBZ#2545042",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545042"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-82458",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-82458"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-82458",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82458"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
          "url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/7xqf651pvjykw0xr9vw0ooz0bwx7wzy7",
          "url": "https://lists.apache.org/thread/7xqf651pvjykw0xr9vw0ooz0bwx7wzy7"
        }
      ],
      "release_date": "2026-10-02T11:30:51.264000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-01T06:16:09+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74369"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ],
      "title": "thrift: thrift: Denial of Service via excessive memory allocation"
    },
    {
      "cve": "CVE-2026-82459",
      "cwe": {
        "id": "CWE-787",
        "name": "Out-of-bounds Write"
      },
      "discovery_date": "2026-10-02T11:41:06.160175+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2545041"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Apache Thrift. A remote, unauthenticated attacker could cause a Denial of Service (DoS) by sending specially crafted network traffic to an affected application. Due to an integer underflow in the 32-bit C++ THeaderTransport component, processing this malformed data triggers an out-of-bounds memory write, leading to an application crash.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "thrift: thrift: Denial of Service via integer underflow in THeaderTransport",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-82459"
        },
        {
          "category": "external",
          "summary": "RHBZ#2545041",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545041"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-82459",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-82459"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-82459",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82459"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
          "url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/zf8ppfpl6nqhp53sxnz6osnjw93g9fw2",
          "url": "https://lists.apache.org/thread/zf8ppfpl6nqhp53sxnz6osnjw93g9fw2"
        }
      ],
      "release_date": "2026-10-02T11:32:30.148000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-01T06:16:09+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74369"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ],
      "title": "thrift: thrift: Denial of Service via integer underflow in THeaderTransport"
    },
    {
      "cve": "CVE-2026-83745",
      "cwe": {
        "id": "CWE-130",
        "name": "Improper Handling of Length Parameter Inconsistency"
      },
      "discovery_date": "2026-10-02T12:24:50.036523+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2545142"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Apache Thrift. A remote attacker can cause a Denial of Service (DoS) against the Node.js and D WebSocket server transports by sending a frame specifying an excessively large payload length. Because the server immediately allocates the declared amount of memory without verifying that the payload data has arrived, an attacker can rapidly exhaust system memory and crash the service.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "thrift: thrift: Denial of Service via excessive memory allocation in WebSocket transport",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-83745"
        },
        {
          "category": "external",
          "summary": "RHBZ#2545142",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545142"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-83745",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-83745"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-83745",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83745"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
          "url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/64y7f0b89mnq4xoqcn4h26to8kskolgc",
          "url": "https://lists.apache.org/thread/64y7f0b89mnq4xoqcn4h26to8kskolgc"
        }
      ],
      "release_date": "2026-10-02T12:16:15.128000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-01T06:16:09+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74369"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ],
      "title": "thrift: thrift: Denial of Service via excessive memory allocation in WebSocket transport"
    },
    {
      "cve": "CVE-2026-85086",
      "cwe": {
        "id": "CWE-295",
        "name": "Improper Certificate Validation"
      },
      "discovery_date": "2026-10-02T11:52:29.698780+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2545053"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Apache Thrift\u0027s Perl bindings. Due to insecure default settings and improper certificate validation, client connections fail to verify the authenticity of remote server certificates. An unauthenticated attacker positioned on the network could exploit this vulnerability to conduct a man-in-the-middle (MitM) attack, allowing them to eavesdrop on or alter transmitted data and resulting in information disclosure.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "thrift: thrift: Information disclosure via improper certificate validation in Perl bindings",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-85086"
        },
        {
          "category": "external",
          "summary": "RHBZ#2545053",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545053"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-85086",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-85086"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-85086",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85086"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
          "url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/c7f9g4027ok0gocyso2y84r2mhgc2xmy",
          "url": "https://lists.apache.org/thread/c7f9g4027ok0gocyso2y84r2mhgc2xmy"
        }
      ],
      "release_date": "2026-10-02T11:34:00.954000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-01T06:16:09+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74369"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 7.4,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ],
      "title": "thrift: thrift: Information disclosure via improper certificate validation in Perl bindings"
    },
    {
      "cve": "CVE-2026-85088",
      "cwe": {
        "id": "CWE-295",
        "name": "Improper Certificate Validation"
      },
      "discovery_date": "2026-10-02T11:59:54.540051+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2545088"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Apache Thrift. During Transport Layer Security (TLS) certificate validation, the client libraries improperly evaluate the certificate\u0027s Common Name (CN) when subject alternative name (SAN) entries do not match the target host. A network-positioned attacker possessing a trusted certificate matching the host\u0027s Common Name can exploit this vulnerability to impersonate the legitimate server. Successful exploitation allows the attacker to intercept or tamper with encrypted communications.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "thrift: thrift: Man-in-the-middle attacks via improper certificate validation",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-85088"
        },
        {
          "category": "external",
          "summary": "RHBZ#2545088",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545088"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-85088",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-85088"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-85088",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85088"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
          "url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/zcgm7lx6037lvgvn87rc1tj3p0zhv371",
          "url": "https://lists.apache.org/thread/zcgm7lx6037lvgvn87rc1tj3p0zhv371"
        }
      ],
      "release_date": "2026-10-02T11:37:14.749000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-01T06:16:09+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74369"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 7.4,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ],
      "title": "thrift: thrift: Man-in-the-middle attacks via improper certificate validation"
    },
    {
      "cve": "CVE-2026-85494",
      "cwe": {
        "id": "CWE-130",
        "name": "Improper Handling of Length Parameter Inconsistency"
      },
      "discovery_date": "2026-10-02T10:54:18.453376+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2545019"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Apache Thrift. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending specially crafted requests to applications utilizing affected language bindings. Flawed input parameter processing and resource allocation can trigger application crashes or excessive resource consumption, rendering the service unavailable.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "thrift: thrift: Denial of Service via improper message handling in language bindings",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-85494"
        },
        {
          "category": "external",
          "summary": "RHBZ#2545019",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545019"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-85494",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-85494"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-85494",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85494"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
          "url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/rm0m34gt6fh1flvt16wty559hfg191qr",
          "url": "https://lists.apache.org/thread/rm0m34gt6fh1flvt16wty559hfg191qr"
        }
      ],
      "release_date": "2026-10-02T10:42:44.813000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-01T06:16:09+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74369"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ],
      "title": "thrift: thrift: Denial of Service via improper message handling in language bindings"
    },
    {
      "cve": "CVE-2026-86535",
      "cwe": {
        "id": "CWE-835",
        "name": "Loop with Unreachable Exit Condition (\u0027Infinite Loop\u0027)"
      },
      "discovery_date": "2026-10-02T12:13:50.425036+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2545128"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Apache Thrift. A remote attacker can exploit this vulnerability by submitting specially crafted messages to applications using the Node.js bindings with TJSONProtocol. Successful exploitation can trigger an infinite loop or cause prototype pollution (unintended modification of shared object attributes), resulting in a Denial of Service (DoS).",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "thrift: thrift: Denial of Service via TJSONProtocol in Node.js bindings",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-86535"
        },
        {
          "category": "external",
          "summary": "RHBZ#2545128",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545128"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-86535",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-86535"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-86535",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86535"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
          "url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/94cvvzzl0rh707bn2j4zt844v547508g",
          "url": "https://lists.apache.org/thread/94cvvzzl0rh707bn2j4zt844v547508g"
        }
      ],
      "release_date": "2026-10-02T11:38:16.628000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-01T06:16:09+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74369"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ],
      "title": "thrift: thrift: Denial of Service via TJSONProtocol in Node.js bindings"
    },
    {
      "cve": "CVE-2026-86537",
      "cwe": {
        "id": "CWE-835",
        "name": "Loop with Unreachable Exit Condition (\u0027Infinite Loop\u0027)"
      },
      "discovery_date": "2026-10-02T12:08:46.104212+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2545121"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Apache Thrift\u0027s D language bindings. A remote, unauthenticated attacker could cause a Denial of Service (DoS) by sending specially crafted input to an affected application. This input triggers an integer underflow or an unhandled exception, causing the process to enter an infinite loop or terminate unexpectedly.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "thrift: thrift: Denial of Service via infinite loop in D language bindings",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-86537"
        },
        {
          "category": "external",
          "summary": "RHBZ#2545121",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545121"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-86537",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-86537"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-86537",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86537"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
          "url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/k14jfr1xwc0vtmm2s7xro6lt7q4y6s7m",
          "url": "https://lists.apache.org/thread/k14jfr1xwc0vtmm2s7xro6lt7q4y6s7m"
        }
      ],
      "release_date": "2026-10-02T11:40:51.704000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-01T06:16:09+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74369"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ],
      "title": "thrift: thrift: Denial of Service via infinite loop in D language bindings"
    },
    {
      "cve": "CVE-2026-90440",
      "cwe": {
        "id": "CWE-248",
        "name": "Uncaught Exception"
      },
      "discovery_date": "2026-10-02T11:54:45.756003+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2545066"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Apache Thrift\u0027s D language implementation within the TNonblockingServer component. Due to improper handling of exceptional conditions and improper resource shutdown, an uncaught exception can occur during server operations. A remote, unauthenticated attacker could exploit this vulnerability to cause a Denial of Service (DoS) by terminating the server process.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "thrift: thrift: Denial of Service via improper exception handling in TNonblockingServer",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-90440"
        },
        {
          "category": "external",
          "summary": "RHBZ#2545066",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545066"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-90440",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-90440"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-90440",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90440"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
          "url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/s8fjltl6c1pkm7vg9v4qkr89b5b74jbg",
          "url": "https://lists.apache.org/thread/s8fjltl6c1pkm7vg9v4qkr89b5b74jbg"
        }
      ],
      "release_date": "2026-10-02T11:44:11.636000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-01T06:16:09+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74369"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ],
      "title": "thrift: thrift: Denial of Service via improper exception handling in TNonblockingServer"
    },
    {
      "cve": "CVE-2026-93925",
      "cwe": {
        "id": "CWE-787",
        "name": "Out-of-bounds Write"
      },
      "discovery_date": "2026-10-02T10:31:47.430017+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2545010"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Apache Thrift. An incorrect bitwise integer shift in the C++ THeaderProtocol implementation can cause a stack-based buffer overflow. A remote, unauthenticated attacker could exploit this vulnerability by sending specially crafted input, resulting in a Denial of Service (DoS) caused by an application crash.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "thrift: thrift: Denial of Service via stack-based buffer overflow in THeaderProtocol",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-93925"
        },
        {
          "category": "external",
          "summary": "RHBZ#2545010",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545010"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-93925",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-93925"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-93925",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-93925"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
          "url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/b4rrkrwoyqb9g7hk58d3fx09cbvp1tg9",
          "url": "https://lists.apache.org/thread/b4rrkrwoyqb9g7hk58d3fx09cbvp1tg9"
        }
      ],
      "release_date": "2026-10-02T10:16:17.913000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-01T06:16:09+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74369"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ],
      "title": "thrift: thrift: Denial of Service via stack-based buffer overflow in THeaderProtocol"
    },
    {
      "cve": "CVE-2026-93926",
      "cwe": {
        "id": "CWE-772",
        "name": "Missing Release of Resource after Effective Lifetime"
      },
      "discovery_date": "2026-10-02T10:31:33.640474+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2545008"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Apache Thrift\u0027s THeaderTransport component. Due to a failure to release allocated memory and system resources after their operational lifetime, a remote attacker can exploit this vulnerability by sending network traffic that repeatedly consumes resources. This issue can cause system memory exhaustion, leading to a Denial of Service (DoS).",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "thrift: thrift: Denial of Service via memory leak in THeaderTransport",
          "title": "Vulnerability summary"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-93926"
        },
        {
          "category": "external",
          "summary": "RHBZ#2545008",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545008"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-93926",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-93926"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-93926",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-93926"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
          "url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/9353rb8mpoq4ltff88h1j2y3hfy6blgb",
          "url": "https://lists.apache.org/thread/9353rb8mpoq4ltff88h1j2y3hfy6blgb"
        }
      ],
      "release_date": "2026-10-02T10:13:55.957000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-01T06:16:09+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74369"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ],
      "title": "thrift: thrift: Denial of Service via memory leak in THeaderTransport"
    },
    {
      "cve": "CVE-2026-94633",
      "cwe": {
        "id": "CWE-770",
        "name": "Allocation of Resources Without Limits or Throttling"
      },
      "discovery_date": "2026-10-02T10:32:20.890715+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2545011"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Apache Thrift\u0027s Dart bindings. An unauthenticated remote attacker can exploit this vulnerability by sending input containing inconsistent length parameters, triggering excessive memory allocation. This can lead to system memory exhaustion, resulting in a Denial of Service (DoS) condition.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "thrift: thrift: Denial of Service via excessive memory allocation in Dart bindings",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-94633"
        },
        {
          "category": "external",
          "summary": "RHBZ#2545011",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545011"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-94633",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-94633"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-94633",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-94633"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
          "url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/cxkbblyht7988p2o6yvnmd6536qmt88k",
          "url": "https://lists.apache.org/thread/cxkbblyht7988p2o6yvnmd6536qmt88k"
        }
      ],
      "release_date": "2026-10-02T10:13:00.027000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-01T06:16:09+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74369"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ],
      "title": "thrift: thrift: Denial of Service via excessive memory allocation in Dart bindings"
    },
    {
      "cve": "CVE-2026-94635",
      "cwe": {
        "id": "CWE-130",
        "name": "Improper Handling of Length Parameter Inconsistency"
      },
      "discovery_date": "2026-10-02T09:32:01.870379+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2544989"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in the Apache Thrift Lua bindings. A remote attacker could exploit this vulnerability by sending requests containing inconsistent length parameters, triggering excessive resource allocation without proper limits. This issue can exhaust available system memory or processing capacity, resulting in a Denial of Service (DoS).",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "thrift: thrift: Denial of Service via improper length parameter handling in Lua bindings",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-94635"
        },
        {
          "category": "external",
          "summary": "RHBZ#2544989",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2544989"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-94635",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-94635"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-94635",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-94635"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
          "url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/ow8994gb5g8ssmmbkbl48xqb0tpvqyr3",
          "url": "https://lists.apache.org/thread/ow8994gb5g8ssmmbkbl48xqb0tpvqyr3"
        }
      ],
      "release_date": "2026-10-02T09:07:56.691000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-01T06:16:09+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74369"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ],
      "title": "thrift: thrift: Denial of Service via improper length parameter handling in Lua bindings"
    },
    {
      "cve": "CVE-2026-94638",
      "cwe": {
        "id": "CWE-770",
        "name": "Allocation of Resources Without Limits or Throttling"
      },
      "discovery_date": "2026-10-02T12:40:39.685068+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2545160"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in the Apache Thrift PHP bindings. Due to a lack of limits or throttling on resource allocation, a remote attacker can send crafted requests that consume excessive system resources. This issue can lead to a Denial of Service (DoS) for the affected service.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "thrift: Apache Thrift: Denial of Service via uncontrolled resource allocation in PHP bindings",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-94638"
        },
        {
          "category": "external",
          "summary": "RHBZ#2545160",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545160"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-94638",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-94638"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-94638",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-94638"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
          "url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/v60w786pqr7njzz9425grby8yjrgmbsj",
          "url": "https://lists.apache.org/thread/v60w786pqr7njzz9425grby8yjrgmbsj"
        }
      ],
      "release_date": "2026-10-02T11:49:43.765000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-01T06:16:09+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74369"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ],
      "title": "thrift: Apache Thrift: Denial of Service via uncontrolled resource allocation in PHP bindings"
    },
    {
      "cve": "CVE-2026-94646",
      "cwe": {
        "id": "CWE-915",
        "name": "Improperly Controlled Modification of Dynamically-Determined Object Attributes"
      },
      "discovery_date": "2026-10-02T12:23:11.847024+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2545138"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Apache Thrift\u0027s Node.js bindings. Due to improper input validation and prototype pollution\u2014a condition where base JavaScript object properties can be modified\u2014the application fails to safely process incoming data. A remote attacker can exploit this vulnerability by sending specially crafted input to trigger an uncaught exception, causing the service to crash and resulting in a Denial of Service (DoS).",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "thrift: thrift: Denial of Service via prototype pollution in Node.js bindings",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-94646"
        },
        {
          "category": "external",
          "summary": "RHBZ#2545138",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545138"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-94646",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-94646"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-94646",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-94646"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
          "url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/5hjh0gz8wf6bo7ydxjpqj92m42hwmfo8",
          "url": "https://lists.apache.org/thread/5hjh0gz8wf6bo7ydxjpqj92m42hwmfo8"
        }
      ],
      "release_date": "2026-10-02T11:52:21.192000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-01T06:16:09+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74369"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ],
      "title": "thrift: thrift: Denial of Service via prototype pollution in Node.js bindings"
    },
    {
      "cve": "CVE-2026-94650",
      "cwe": {
        "id": "CWE-770",
        "name": "Allocation of Resources Without Limits or Throttling"
      },
      "discovery_date": "2026-10-02T11:01:28.298445+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2545020"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Apache Thrift. An uncontrolled recursion vulnerability in the C (GLib) library bindings allows a remote, unauthenticated attacker to send specially crafted input to an affected application. Processing this input triggers excessive nested function calls that exhaust stack memory, causing an application crash and resulting in a Denial of Service (DoS).",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "thrift: thrift: Denial of Service via uncontrolled recursion in C GLib bindings",
          "title": "Vulnerability summary"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-94650"
        },
        {
          "category": "external",
          "summary": "RHBZ#2545020",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545020"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-94650",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-94650"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-94650",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-94650"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
          "url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/poskkt3p754b2f293g63934hw160o86j",
          "url": "https://lists.apache.org/thread/poskkt3p754b2f293g63934hw160o86j"
        }
      ],
      "release_date": "2026-10-02T10:49:37.521000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-01T06:16:09+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74369"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ],
      "title": "thrift: thrift: Denial of Service via uncontrolled recursion in C GLib bindings"
    },
    {
      "cve": "CVE-2026-94657",
      "cwe": {
        "id": "CWE-770",
        "name": "Allocation of Resources Without Limits or Throttling"
      },
      "discovery_date": "2026-10-02T12:27:57.067572+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2545148"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Apache Thrift. A remote attacker could exploit improper resource allocation controls in the JavaME bindings to cause a Denial of Service (DoS). By sending requests that trigger unbounded resource consumption, an attacker can exhaust system resources and make the service unavailable.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "thrift: thrift: Denial of Service via improper resource allocation in JavaME bindings",
          "title": "Vulnerability summary"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-94657"
        },
        {
          "category": "external",
          "summary": "RHBZ#2545148",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545148"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-94657",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-94657"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-94657",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-94657"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
          "url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/lpcmo2xjfyfww474xdyyfypkqthk9s14",
          "url": "https://lists.apache.org/thread/lpcmo2xjfyfww474xdyyfypkqthk9s14"
        }
      ],
      "release_date": "2026-10-02T12:01:36.606000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-01T06:16:09+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74369"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ],
      "title": "thrift: thrift: Denial of Service via improper resource allocation in JavaME bindings"
    },
    {
      "cve": "CVE-2026-96277",
      "cwe": {
        "id": "CWE-248",
        "name": "Uncaught Exception"
      },
      "discovery_date": "2026-10-02T12:39:08.569139+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2545159"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in the Apache Thrift Ruby bindings. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) due to improper handling of exceptional conditions. By triggering an uncaught exception, an attacker can crash the service and disrupt availability.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "thrift: thrift: Denial of Service via uncaught exception in Ruby bindings",
          "title": "Vulnerability summary"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-96277"
        },
        {
          "category": "external",
          "summary": "RHBZ#2545159",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545159"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-96277",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-96277"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-96277",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-96277"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
          "url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/k1t5r9sz7k5tn57cnf5khw2ywlxv6098",
          "url": "https://lists.apache.org/thread/k1t5r9sz7k5tn57cnf5khw2ywlxv6098"
        }
      ],
      "release_date": "2026-10-02T12:03:23.964000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-01T06:16:09+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74369"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ],
      "title": "thrift: thrift: Denial of Service via uncaught exception in Ruby bindings"
    },
    {
      "cve": "CVE-2026-96292",
      "cwe": {
        "id": "CWE-1333",
        "name": "Inefficient Regular Expression Complexity"
      },
      "discovery_date": "2026-10-02T11:30:57.884653+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2545035"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Apache Thrift\u0027s Lua bindings. A remote attacker could exploit this vulnerability by sending specially crafted input that triggers inefficient regular expression processing. This can cause excessive resource consumption, resulting in a Denial of Service (DoS) on the affected service.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "thrift: thrift: Denial of Service via inefficient regular expression evaluation in Lua bindings",
          "title": "Vulnerability summary"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
          "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
          "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
          "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-96292"
        },
        {
          "category": "external",
          "summary": "RHBZ#2545035",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545035"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-96292",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-96292"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-96292",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-96292"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
          "url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/3wmvtvv56rky5wtszn4zr8w12kg928qn",
          "url": "https://lists.apache.org/thread/3wmvtvv56rky5wtszn4zr8w12kg928qn"
        }
      ],
      "release_date": "2026-10-02T11:11:33.256000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-01T06:16:09+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
            "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
            "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
            "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74369"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ],
      "title": "thrift: thrift: Denial of Service via inefficient regular expression evaluation in Lua bindings"
    }
  ]
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Detection rules are retrieved from Rulezet.

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…