RHSA-2026:74369
Vulnerability from csaf_redhat - Published: 2026-10-01 06:16 - Updated: 2026-10-02 22:10A flaw was found in the Apache Thrift C++ bindings. A remote, unauthenticated attacker could cause a Denial of Service (DoS) by sending specially crafted, highly compressed data payloads. Because the software does not properly restrict resource allocation during decompression, processing these payloads can exhaust system resources and render the service unavailable.
| Product | Identifier | Version | Remediation |
|---|---|---|---|
| Unresolved product id: Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms | — |
Vendor Fix
fix
|
|
| Unresolved product id: Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms | — |
Vendor Fix
fix
|
|
| Unresolved product id: Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64 | — |
Vendor Fix
fix
|
|
| Unresolved product id: Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64 | — |
Vendor Fix
fix
|
|
| Unresolved product id: Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64 | — |
Vendor Fix
fix
|
|
| Unresolved product id: Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src | — |
Vendor Fix
fix
|
|
| Unresolved product id: Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64 | — |
Vendor Fix
fix
|
|
| Unresolved product id: Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64 | — |
Vendor Fix
fix
|
|
| Unresolved product id: Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64 | — |
Vendor Fix
fix
|
|
| Unresolved product id: Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64 | — |
Vendor Fix
fix
|
|
| Unresolved product id: Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64 | — |
Vendor Fix
fix
|
|
| Unresolved product id: Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64 | — |
Vendor Fix
fix
|
|
| Unresolved product id: Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64 | — |
Vendor Fix
fix
|
A flaw was found in Apache Thrift's C GLib bindings. A remote, unauthenticated attacker could exploit this vulnerability by sending specially crafted input that triggers the access of an uninitialized pointer. This access can cause the application to crash, resulting in a Denial of Service (DoS).
CWE-824 - Access of Uninitialized PointerA flaw was found in Apache Thrift's Delphi bindings buffered transport. The component fails to properly restrict or throttle resource allocation when processing input. A remote, unauthenticated attacker could exploit this vulnerability to consume excessive system resources, resulting in a Denial of Service (DoS).
A flaw was found in Apache Thrift. An integer overflow within the PHP bindings leads to a stack-based buffer overflow when processing specially crafted data. A remote, unauthenticated attacker could exploit this flaw to crash the service, leading to a Denial of Service (DoS).
A flaw was found in Apache Thrift. Multiple language bindings fail to enforce recursion limits when processing skipped fields in incoming messages. A remote, unauthenticated attacker can exploit this vulnerability by sending a message containing deeply nested unknown fields, leading to stack exhaustion and causing a Denial of Service (DoS) through an application crash.
A flaw was found in Apache Thrift. Multiple language bindings fail to properly restrict memory allocation when processing input containing excessive size values. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted requests, consuming available memory and causing a Denial of Service (DoS).
A flaw was found in Apache Thrift. A remote, unauthenticated attacker could cause a Denial of Service (DoS) by sending specially crafted network traffic to an affected application. Due to an integer underflow in the 32-bit C++ THeaderTransport component, processing this malformed data triggers an out-of-bounds memory write, leading to an application crash.
A flaw was found in Apache Thrift. A remote attacker can cause a Denial of Service (DoS) against the Node.js and D WebSocket server transports by sending a frame specifying an excessively large payload length. Because the server immediately allocates the declared amount of memory without verifying that the payload data has arrived, an attacker can rapidly exhaust system memory and crash the service.
A flaw was found in Apache Thrift's Perl bindings. Due to insecure default settings and improper certificate validation, client connections fail to verify the authenticity of remote server certificates. An unauthenticated attacker positioned on the network could exploit this vulnerability to conduct a man-in-the-middle (MitM) attack, allowing them to eavesdrop on or alter transmitted data and resulting in information disclosure.
A flaw was found in Apache Thrift. During Transport Layer Security (TLS) certificate validation, the client libraries improperly evaluate the certificate's Common Name (CN) when subject alternative name (SAN) entries do not match the target host. A network-positioned attacker possessing a trusted certificate matching the host's Common Name can exploit this vulnerability to impersonate the legitimate server. Successful exploitation allows the attacker to intercept or tamper with encrypted communications.
A flaw was found in Apache Thrift. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending specially crafted requests to applications utilizing affected language bindings. Flawed input parameter processing and resource allocation can trigger application crashes or excessive resource consumption, rendering the service unavailable.
A flaw was found in Apache Thrift. A remote attacker can exploit this vulnerability by submitting specially crafted messages to applications using the Node.js bindings with TJSONProtocol. Successful exploitation can trigger an infinite loop or cause prototype pollution (unintended modification of shared object attributes), resulting in a Denial of Service (DoS).
A flaw was found in Apache Thrift's D language bindings. A remote, unauthenticated attacker could cause a Denial of Service (DoS) by sending specially crafted input to an affected application. This input triggers an integer underflow or an unhandled exception, causing the process to enter an infinite loop or terminate unexpectedly.
A flaw was found in Apache Thrift's D language implementation within the TNonblockingServer component. Due to improper handling of exceptional conditions and improper resource shutdown, an uncaught exception can occur during server operations. A remote, unauthenticated attacker could exploit this vulnerability to cause a Denial of Service (DoS) by terminating the server process.
A flaw was found in Apache Thrift. An incorrect bitwise integer shift in the C++ THeaderProtocol implementation can cause a stack-based buffer overflow. A remote, unauthenticated attacker could exploit this vulnerability by sending specially crafted input, resulting in a Denial of Service (DoS) caused by an application crash.
A flaw was found in Apache Thrift's THeaderTransport component. Due to a failure to release allocated memory and system resources after their operational lifetime, a remote attacker can exploit this vulnerability by sending network traffic that repeatedly consumes resources. This issue can cause system memory exhaustion, leading to a Denial of Service (DoS).
CWE-772 - Missing Release of Resource after Effective LifetimeA flaw was found in Apache Thrift's Dart bindings. An unauthenticated remote attacker can exploit this vulnerability by sending input containing inconsistent length parameters, triggering excessive memory allocation. This can lead to system memory exhaustion, resulting in a Denial of Service (DoS) condition.
A flaw was found in the Apache Thrift Lua bindings. A remote attacker could exploit this vulnerability by sending requests containing inconsistent length parameters, triggering excessive resource allocation without proper limits. This issue can exhaust available system memory or processing capacity, resulting in a Denial of Service (DoS).
A flaw was found in the Apache Thrift PHP bindings. Due to a lack of limits or throttling on resource allocation, a remote attacker can send crafted requests that consume excessive system resources. This issue can lead to a Denial of Service (DoS) for the affected service.
A flaw was found in Apache Thrift's Node.js bindings. Due to improper input validation and prototype pollution—a condition where base JavaScript object properties can be modified—the application fails to safely process incoming data. A remote attacker can exploit this vulnerability by sending specially crafted input to trigger an uncaught exception, causing the service to crash and resulting in a Denial of Service (DoS).
A flaw was found in Apache Thrift. An uncontrolled recursion vulnerability in the C (GLib) library bindings allows a remote, unauthenticated attacker to send specially crafted input to an affected application. Processing this input triggers excessive nested function calls that exhaust stack memory, causing an application crash and resulting in a Denial of Service (DoS).
CWE-770 - Allocation of Resources Without Limits or ThrottlingA flaw was found in Apache Thrift. A remote attacker could exploit improper resource allocation controls in the JavaME bindings to cause a Denial of Service (DoS). By sending requests that trigger unbounded resource consumption, an attacker can exhaust system resources and make the service unavailable.
CWE-770 - Allocation of Resources Without Limits or ThrottlingA flaw was found in the Apache Thrift Ruby bindings. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) due to improper handling of exceptional conditions. By triggering an uncaught exception, an attacker can crash the service and disrupt availability.
CWE-248 - Uncaught ExceptionA flaw was found in Apache Thrift's Lua bindings. A remote attacker could exploit this vulnerability by sending specially crafted input that triggers inefficient regular expression processing. This can cause excessive resource consumption, resulting in a Denial of Service (DoS) on the affected service.
CWE-1333 - Inefficient Regular Expression Complexity{
"document": {
"aggregate_severity": {
"namespace": "https://access.redhat.com/security/updates/classification/",
"text": "Important"
},
"category": "csaf_security_advisory",
"csaf_version": "2.0",
"distribution": {
"text": "Copyright \u00a9 Red Hat, Inc. All rights reserved.",
"tlp": {
"label": "WHITE",
"url": "https://www.first.org/tlp/"
}
},
"lang": "en",
"notes": [
{
"category": "summary",
"text": "An update for Red Hat Hardened Images RPMs is now available.",
"title": "Topic"
},
{
"category": "general",
"text": "This update includes the following RPMs:\n\nthrift:\n * perl-thrift-0.25.0-0.1.hum1 (noarch)\n * python3-thrift-0.25.0-0.1.hum1 (aarch64, x86_64)\n * thrift-0.25.0-0.1.hum1 (aarch64, x86_64)\n * thrift-devel-0.25.0-0.1.hum1 (aarch64, x86_64)\n * thrift-glib-0.25.0-0.1.hum1 (aarch64, x86_64)\n * thrift-qt-0.25.0-0.1.hum1 (aarch64, x86_64)\n * thrift-0.25.0-0.1.hum1.src (src)",
"title": "Details"
},
{
"category": "legal_disclaimer",
"text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
"title": "Terms of Use"
}
],
"publisher": {
"category": "vendor",
"contact_details": "https://access.redhat.com/security/team/contact/",
"issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
"name": "Red Hat Product Security",
"namespace": "https://www.redhat.com"
},
"references": [
{
"category": "self",
"summary": "https://access.redhat.com/errata/RHSA-2026:74369",
"url": "https://access.redhat.com/errata/RHSA-2026:74369"
},
{
"category": "external",
"summary": "https://images.redhat.com/",
"url": "https://images.redhat.com/"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-94635",
"url": "https://access.redhat.com/security/cve/CVE-2026-94635"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/updates/classification/",
"url": "https://access.redhat.com/security/updates/classification/"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-93926",
"url": "https://access.redhat.com/security/cve/CVE-2026-93926"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-94634",
"url": "https://access.redhat.com/security/cve/CVE-2026-94634"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-93925",
"url": "https://access.redhat.com/security/cve/CVE-2026-93925"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-94633",
"url": "https://access.redhat.com/security/cve/CVE-2026-94633"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-85483",
"url": "https://access.redhat.com/security/cve/CVE-2026-85483"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-85494",
"url": "https://access.redhat.com/security/cve/CVE-2026-85494"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-91137",
"url": "https://access.redhat.com/security/cve/CVE-2026-91137"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-85087",
"url": "https://access.redhat.com/security/cve/CVE-2026-85087"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-87117",
"url": "https://access.redhat.com/security/cve/CVE-2026-87117"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-90440",
"url": "https://access.redhat.com/security/cve/CVE-2026-90440"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-94650",
"url": "https://access.redhat.com/security/cve/CVE-2026-94650"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-96294",
"url": "https://access.redhat.com/security/cve/CVE-2026-96294"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-94644",
"url": "https://access.redhat.com/security/cve/CVE-2026-94644"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-85086",
"url": "https://access.redhat.com/security/cve/CVE-2026-85086"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-82458",
"url": "https://access.redhat.com/security/cve/CVE-2026-82458"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-96990",
"url": "https://access.redhat.com/security/cve/CVE-2026-96990"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-94645",
"url": "https://access.redhat.com/security/cve/CVE-2026-94645"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-82459",
"url": "https://access.redhat.com/security/cve/CVE-2026-82459"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-85493",
"url": "https://access.redhat.com/security/cve/CVE-2026-85493"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-96292",
"url": "https://access.redhat.com/security/cve/CVE-2026-96292"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-96288",
"url": "https://access.redhat.com/security/cve/CVE-2026-96288"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-66331",
"url": "https://access.redhat.com/security/cve/CVE-2026-66331"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-83745",
"url": "https://access.redhat.com/security/cve/CVE-2026-83745"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-94638",
"url": "https://access.redhat.com/security/cve/CVE-2026-94638"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-94654",
"url": "https://access.redhat.com/security/cve/CVE-2026-94654"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-94657",
"url": "https://access.redhat.com/security/cve/CVE-2026-94657"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-96277",
"url": "https://access.redhat.com/security/cve/CVE-2026-96277"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-86535",
"url": "https://access.redhat.com/security/cve/CVE-2026-86535"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-92834",
"url": "https://access.redhat.com/security/cve/CVE-2026-92834"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-94652",
"url": "https://access.redhat.com/security/cve/CVE-2026-94652"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-85088",
"url": "https://access.redhat.com/security/cve/CVE-2026-85088"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-86536",
"url": "https://access.redhat.com/security/cve/CVE-2026-86536"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-94658",
"url": "https://access.redhat.com/security/cve/CVE-2026-94658"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-66837",
"url": "https://access.redhat.com/security/cve/CVE-2026-66837"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-96289",
"url": "https://access.redhat.com/security/cve/CVE-2026-96289"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-66859",
"url": "https://access.redhat.com/security/cve/CVE-2026-66859"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-94646",
"url": "https://access.redhat.com/security/cve/CVE-2026-94646"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-96287",
"url": "https://access.redhat.com/security/cve/CVE-2026-96287"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-96286",
"url": "https://access.redhat.com/security/cve/CVE-2026-96286"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-85476",
"url": "https://access.redhat.com/security/cve/CVE-2026-85476"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-66054",
"url": "https://access.redhat.com/security/cve/CVE-2026-66054"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-94636",
"url": "https://access.redhat.com/security/cve/CVE-2026-94636"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-94656",
"url": "https://access.redhat.com/security/cve/CVE-2026-94656"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-66858",
"url": "https://access.redhat.com/security/cve/CVE-2026-66858"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-66081",
"url": "https://access.redhat.com/security/cve/CVE-2026-66081"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-94655",
"url": "https://access.redhat.com/security/cve/CVE-2026-94655"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-66055",
"url": "https://access.redhat.com/security/cve/CVE-2026-66055"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-94648",
"url": "https://access.redhat.com/security/cve/CVE-2026-94648"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-94653",
"url": "https://access.redhat.com/security/cve/CVE-2026-94653"
},
{
"category": "external",
"summary": "https://access.redhat.com/security/cve/CVE-2026-86537",
"url": "https://access.redhat.com/security/cve/CVE-2026-86537"
},
{
"category": "self",
"summary": "Canonical URL",
"url": "https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_74369.json"
}
],
"title": "Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update",
"tracking": {
"current_release_date": "2026-10-02T22:10:24+00:00",
"generator": {
"date": "2026-10-02T22:10:24+00:00",
"engine": {
"name": "Red Hat SDEngine",
"version": "5.4.0"
}
},
"id": "RHSA-2026:74369",
"initial_release_date": "2026-10-01T06:16:09+00:00",
"revision_history": [
{
"date": "2026-10-01T06:16:09+00:00",
"number": "1",
"summary": "Initial version"
},
{
"date": "2026-10-02T16:32:28+00:00",
"number": "2",
"summary": "Last updated version"
},
{
"date": "2026-10-02T22:10:24+00:00",
"number": "3",
"summary": "Last generated version"
}
],
"status": "final",
"version": "3"
}
},
"product_tree": {
"branches": [
{
"branches": [
{
"branches": [
{
"category": "product_name",
"name": "Red Hat Hardened Images",
"product": {
"name": "Red Hat Hardened Images",
"product_id": "Red Hat Hardened Images",
"product_identification_helper": {
"cpe": "cpe:/a:redhat:hummingbird:1"
}
}
}
],
"category": "product_family",
"name": "Red Hat Hardened Images"
},
{
"branches": [
{
"category": "product_version",
"name": "perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"product": {
"name": "perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"product_id": "perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"product_identification_helper": {
"purl": "pkg:rpm/redhat/perl-thrift@0.25.0-0.1.hum1?arch=noarch\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-aarch64-rpms"
}
}
},
{
"category": "product_version",
"name": "perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"product": {
"name": "perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"product_id": "perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"product_identification_helper": {
"purl": "pkg:rpm/redhat/perl-thrift@0.25.0-0.1.hum1?arch=noarch\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-x86_64-rpms"
}
}
}
],
"category": "architecture",
"name": "noarch"
},
{
"branches": [
{
"category": "product_version",
"name": "python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"product": {
"name": "python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"product_id": "python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"product_identification_helper": {
"purl": "pkg:rpm/redhat/python3-thrift@0.25.0-0.1.hum1?arch=aarch64\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-aarch64-rpms"
}
}
},
{
"category": "product_version",
"name": "thrift-0:0.25.0-0.1.hum1@aarch64",
"product": {
"name": "thrift-0:0.25.0-0.1.hum1@aarch64",
"product_id": "thrift-0:0.25.0-0.1.hum1@aarch64",
"product_identification_helper": {
"purl": "pkg:rpm/redhat/thrift@0.25.0-0.1.hum1?arch=aarch64\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-aarch64-rpms"
}
}
},
{
"category": "product_version",
"name": "thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"product": {
"name": "thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"product_id": "thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"product_identification_helper": {
"purl": "pkg:rpm/redhat/thrift-devel@0.25.0-0.1.hum1?arch=aarch64\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-aarch64-rpms"
}
}
},
{
"category": "product_version",
"name": "thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"product": {
"name": "thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"product_id": "thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"product_identification_helper": {
"purl": "pkg:rpm/redhat/thrift-glib@0.25.0-0.1.hum1?arch=aarch64\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-aarch64-rpms"
}
}
},
{
"category": "product_version",
"name": "thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"product": {
"name": "thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"product_id": "thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"product_identification_helper": {
"purl": "pkg:rpm/redhat/thrift-qt@0.25.0-0.1.hum1?arch=aarch64\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-aarch64-rpms"
}
}
}
],
"category": "architecture",
"name": "aarch64"
},
{
"branches": [
{
"category": "product_version",
"name": "python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"product": {
"name": "python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"product_id": "python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"product_identification_helper": {
"purl": "pkg:rpm/redhat/python3-thrift@0.25.0-0.1.hum1?arch=x86_64\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-x86_64-rpms"
}
}
},
{
"category": "product_version",
"name": "thrift-0:0.25.0-0.1.hum1@x86_64",
"product": {
"name": "thrift-0:0.25.0-0.1.hum1@x86_64",
"product_id": "thrift-0:0.25.0-0.1.hum1@x86_64",
"product_identification_helper": {
"purl": "pkg:rpm/redhat/thrift@0.25.0-0.1.hum1?arch=x86_64\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-x86_64-rpms"
}
}
},
{
"category": "product_version",
"name": "thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"product": {
"name": "thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"product_id": "thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"product_identification_helper": {
"purl": "pkg:rpm/redhat/thrift-devel@0.25.0-0.1.hum1?arch=x86_64\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-x86_64-rpms"
}
}
},
{
"category": "product_version",
"name": "thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"product": {
"name": "thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"product_id": "thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"product_identification_helper": {
"purl": "pkg:rpm/redhat/thrift-glib@0.25.0-0.1.hum1?arch=x86_64\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-x86_64-rpms"
}
}
},
{
"category": "product_version",
"name": "thrift-qt-0:0.25.0-0.1.hum1@x86_64",
"product": {
"name": "thrift-qt-0:0.25.0-0.1.hum1@x86_64",
"product_id": "thrift-qt-0:0.25.0-0.1.hum1@x86_64",
"product_identification_helper": {
"purl": "pkg:rpm/redhat/thrift-qt@0.25.0-0.1.hum1?arch=x86_64\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-x86_64-rpms"
}
}
}
],
"category": "architecture",
"name": "x86_64"
},
{
"branches": [
{
"category": "product_version",
"name": "thrift-0:0.25.0-0.1.hum1@src",
"product": {
"name": "thrift-0:0.25.0-0.1.hum1@src",
"product_id": "thrift-0:0.25.0-0.1.hum1@src",
"product_identification_helper": {
"purl": "pkg:rpm/redhat/thrift@0.25.0-0.1.hum1?arch=src\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-source-rpms"
}
}
}
],
"category": "architecture",
"name": "src"
}
],
"category": "vendor",
"name": "Red Hat"
}
],
"relationships": [
{
"category": "default_component_of",
"full_product_name": {
"name": "perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms as a component of Red Hat Hardened Images",
"product_id": "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms"
},
"product_reference": "perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"relates_to_product_reference": "Red Hat Hardened Images"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms as a component of Red Hat Hardened Images",
"product_id": "Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms"
},
"product_reference": "perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"relates_to_product_reference": "Red Hat Hardened Images"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "python3-thrift-0:0.25.0-0.1.hum1@aarch64 as a component of Red Hat Hardened Images",
"product_id": "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64"
},
"product_reference": "python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"relates_to_product_reference": "Red Hat Hardened Images"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "python3-thrift-0:0.25.0-0.1.hum1@x86_64 as a component of Red Hat Hardened Images",
"product_id": "Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64"
},
"product_reference": "python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"relates_to_product_reference": "Red Hat Hardened Images"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "thrift-0:0.25.0-0.1.hum1@aarch64 as a component of Red Hat Hardened Images",
"product_id": "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64"
},
"product_reference": "thrift-0:0.25.0-0.1.hum1@aarch64",
"relates_to_product_reference": "Red Hat Hardened Images"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "thrift-0:0.25.0-0.1.hum1@src as a component of Red Hat Hardened Images",
"product_id": "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src"
},
"product_reference": "thrift-0:0.25.0-0.1.hum1@src",
"relates_to_product_reference": "Red Hat Hardened Images"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "thrift-0:0.25.0-0.1.hum1@x86_64 as a component of Red Hat Hardened Images",
"product_id": "Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64"
},
"product_reference": "thrift-0:0.25.0-0.1.hum1@x86_64",
"relates_to_product_reference": "Red Hat Hardened Images"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "thrift-devel-0:0.25.0-0.1.hum1@aarch64 as a component of Red Hat Hardened Images",
"product_id": "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64"
},
"product_reference": "thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"relates_to_product_reference": "Red Hat Hardened Images"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "thrift-devel-0:0.25.0-0.1.hum1@x86_64 as a component of Red Hat Hardened Images",
"product_id": "Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64"
},
"product_reference": "thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"relates_to_product_reference": "Red Hat Hardened Images"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "thrift-glib-0:0.25.0-0.1.hum1@aarch64 as a component of Red Hat Hardened Images",
"product_id": "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64"
},
"product_reference": "thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"relates_to_product_reference": "Red Hat Hardened Images"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "thrift-glib-0:0.25.0-0.1.hum1@x86_64 as a component of Red Hat Hardened Images",
"product_id": "Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64"
},
"product_reference": "thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"relates_to_product_reference": "Red Hat Hardened Images"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "thrift-qt-0:0.25.0-0.1.hum1@aarch64 as a component of Red Hat Hardened Images",
"product_id": "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64"
},
"product_reference": "thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"relates_to_product_reference": "Red Hat Hardened Images"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "thrift-qt-0:0.25.0-0.1.hum1@x86_64 as a component of Red Hat Hardened Images",
"product_id": "Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
},
"product_reference": "thrift-qt-0:0.25.0-0.1.hum1@x86_64",
"relates_to_product_reference": "Red Hat Hardened Images"
}
]
},
"vulnerabilities": [
{
"cve": "CVE-2026-66054",
"cwe": {
"id": "CWE-409",
"name": "Improper Handling of Highly Compressed Data (Data Amplification)"
},
"discovery_date": "2026-10-02T13:14:14.506786+00:00",
"ids": [
{
"system_name": "Red Hat Bugzilla ID",
"text": "2545180"
}
],
"notes": [
{
"category": "description",
"text": "A flaw was found in the Apache Thrift C++ bindings. A remote, unauthenticated attacker could cause a Denial of Service (DoS) by sending specially crafted, highly compressed data payloads. Because the software does not properly restrict resource allocation during decompression, processing these payloads can exhaust system resources and render the service unavailable.",
"title": "Vulnerability description"
},
{
"category": "summary",
"text": "thrift: thrift: Denial of Service via improper handling of compressed data",
"title": "Vulnerability summary"
},
{
"category": "general",
"text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
"title": "CVSS score applicability"
}
],
"product_status": {
"fixed": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
},
"references": [
{
"category": "self",
"summary": "Canonical URL",
"url": "https://access.redhat.com/security/cve/CVE-2026-66054"
},
{
"category": "external",
"summary": "RHBZ#2545180",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545180"
},
{
"category": "external",
"summary": "https://www.cve.org/CVERecord?id=CVE-2026-66054",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-66054"
},
{
"category": "external",
"summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-66054",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66054"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
"url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/7c23sgowkb3ssmolqofqsn8wzsddvf33",
"url": "https://lists.apache.org/thread/7c23sgowkb3ssmolqofqsn8wzsddvf33"
}
],
"release_date": "2026-10-02T12:58:05.610000+00:00",
"remediations": [
{
"category": "vendor_fix",
"date": "2026-10-01T06:16:09+00:00",
"details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
"product_ids": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
],
"restart_required": {
"category": "none"
},
"url": "https://access.redhat.com/errata/RHSA-2026:74369"
}
],
"scores": [
{
"cvss_v3": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
}
],
"threats": [
{
"category": "impact",
"details": "Important"
}
],
"title": "thrift: thrift: Denial of Service via improper handling of compressed data"
},
{
"cve": "CVE-2026-66081",
"cwe": {
"id": "CWE-824",
"name": "Access of Uninitialized Pointer"
},
"discovery_date": "2026-10-02T12:54:48.102391+00:00",
"ids": [
{
"system_name": "Red Hat Bugzilla ID",
"text": "2545165"
}
],
"notes": [
{
"category": "description",
"text": "A flaw was found in Apache Thrift\u0027s C GLib bindings. A remote, unauthenticated attacker could exploit this vulnerability by sending specially crafted input that triggers the access of an uninitialized pointer. This access can cause the application to crash, resulting in a Denial of Service (DoS).",
"title": "Vulnerability description"
},
{
"category": "summary",
"text": "thrift: thrift: Denial of Service via uninitialized pointer access in c_glib bindings",
"title": "Vulnerability summary"
}
],
"product_status": {
"fixed": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
},
"references": [
{
"category": "self",
"summary": "Canonical URL",
"url": "https://access.redhat.com/security/cve/CVE-2026-66081"
},
{
"category": "external",
"summary": "RHBZ#2545165",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545165"
},
{
"category": "external",
"summary": "https://www.cve.org/CVERecord?id=CVE-2026-66081",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-66081"
},
{
"category": "external",
"summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-66081",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66081"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
"url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/9d51ygo6hrsdo5ndwckbwt3mnp290m57",
"url": "https://lists.apache.org/thread/9d51ygo6hrsdo5ndwckbwt3mnp290m57"
}
],
"release_date": "2026-10-02T12:33:13.645000+00:00",
"remediations": [
{
"category": "vendor_fix",
"date": "2026-10-01T06:16:09+00:00",
"details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
"product_ids": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
],
"restart_required": {
"category": "none"
},
"url": "https://access.redhat.com/errata/RHSA-2026:74369"
}
],
"threats": [
{
"category": "impact",
"details": "Important"
}
],
"title": "thrift: thrift: Denial of Service via uninitialized pointer access in c_glib bindings"
},
{
"cve": "CVE-2026-66331",
"cwe": {
"id": "CWE-770",
"name": "Allocation of Resources Without Limits or Throttling"
},
"discovery_date": "2026-10-02T13:00:06.119575+00:00",
"ids": [
{
"system_name": "Red Hat Bugzilla ID",
"text": "2545175"
}
],
"notes": [
{
"category": "description",
"text": "A flaw was found in Apache Thrift\u0027s Delphi bindings buffered transport. The component fails to properly restrict or throttle resource allocation when processing input. A remote, unauthenticated attacker could exploit this vulnerability to consume excessive system resources, resulting in a Denial of Service (DoS).",
"title": "Vulnerability description"
},
{
"category": "summary",
"text": "thrift: thrift: Denial of Service via excessive resource allocation in Delphi buffered transport",
"title": "Vulnerability summary"
},
{
"category": "general",
"text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
"title": "CVSS score applicability"
}
],
"product_status": {
"fixed": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
},
"references": [
{
"category": "self",
"summary": "Canonical URL",
"url": "https://access.redhat.com/security/cve/CVE-2026-66331"
},
{
"category": "external",
"summary": "RHBZ#2545175",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545175"
},
{
"category": "external",
"summary": "https://www.cve.org/CVERecord?id=CVE-2026-66331",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-66331"
},
{
"category": "external",
"summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-66331",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66331"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
"url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/971572orz86jdwlg58wqv8o50oqqb143",
"url": "https://lists.apache.org/thread/971572orz86jdwlg58wqv8o50oqqb143"
}
],
"release_date": "2026-10-02T12:32:46.166000+00:00",
"remediations": [
{
"category": "vendor_fix",
"date": "2026-10-01T06:16:09+00:00",
"details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
"product_ids": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
],
"restart_required": {
"category": "none"
},
"url": "https://access.redhat.com/errata/RHSA-2026:74369"
}
],
"scores": [
{
"cvss_v3": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"products": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
}
],
"threats": [
{
"category": "impact",
"details": "Moderate"
}
],
"title": "thrift: thrift: Denial of Service via excessive resource allocation in Delphi buffered transport"
},
{
"cve": "CVE-2026-66837",
"cwe": {
"id": "CWE-787",
"name": "Out-of-bounds Write"
},
"discovery_date": "2026-10-02T12:53:32.129609+00:00",
"ids": [
{
"system_name": "Red Hat Bugzilla ID",
"text": "2545163"
}
],
"notes": [
{
"category": "description",
"text": "A flaw was found in Apache Thrift. An integer overflow within the PHP bindings leads to a stack-based buffer overflow when processing specially crafted data. A remote, unauthenticated attacker could exploit this flaw to crash the service, leading to a Denial of Service (DoS).",
"title": "Vulnerability description"
},
{
"category": "summary",
"text": "thrift: thrift: Denial of Service via buffer overflow in PHP bindings",
"title": "Vulnerability summary"
},
{
"category": "general",
"text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
"title": "CVSS score applicability"
}
],
"product_status": {
"fixed": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
},
"references": [
{
"category": "self",
"summary": "Canonical URL",
"url": "https://access.redhat.com/security/cve/CVE-2026-66837"
},
{
"category": "external",
"summary": "RHBZ#2545163",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545163"
},
{
"category": "external",
"summary": "https://www.cve.org/CVERecord?id=CVE-2026-66837",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-66837"
},
{
"category": "external",
"summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-66837",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66837"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
"url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/7o985t84551tpo55v6fsd3g42gs3zps1",
"url": "https://lists.apache.org/thread/7o985t84551tpo55v6fsd3g42gs3zps1"
}
],
"release_date": "2026-10-02T12:29:09.189000+00:00",
"remediations": [
{
"category": "vendor_fix",
"date": "2026-10-01T06:16:09+00:00",
"details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
"product_ids": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
],
"restart_required": {
"category": "none"
},
"url": "https://access.redhat.com/errata/RHSA-2026:74369"
}
],
"scores": [
{
"cvss_v3": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
}
],
"threats": [
{
"category": "impact",
"details": "Important"
}
],
"title": "thrift: thrift: Denial of Service via buffer overflow in PHP bindings"
},
{
"cve": "CVE-2026-66858",
"cwe": {
"id": "CWE-770",
"name": "Allocation of Resources Without Limits or Throttling"
},
"discovery_date": "2026-10-02T12:56:52.055546+00:00",
"ids": [
{
"system_name": "Red Hat Bugzilla ID",
"text": "2545169"
}
],
"notes": [
{
"category": "description",
"text": "A flaw was found in Apache Thrift. Multiple language bindings fail to enforce recursion limits when processing skipped fields in incoming messages. A remote, unauthenticated attacker can exploit this vulnerability by sending a message containing deeply nested unknown fields, leading to stack exhaustion and causing a Denial of Service (DoS) through an application crash.",
"title": "Vulnerability description"
},
{
"category": "summary",
"text": "thrift: Apache Thrift: Denial of Service via deeply nested unknown fields",
"title": "Vulnerability summary"
},
{
"category": "general",
"text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
"title": "CVSS score applicability"
}
],
"product_status": {
"fixed": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
},
"references": [
{
"category": "self",
"summary": "Canonical URL",
"url": "https://access.redhat.com/security/cve/CVE-2026-66858"
},
{
"category": "external",
"summary": "RHBZ#2545169",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545169"
},
{
"category": "external",
"summary": "https://www.cve.org/CVERecord?id=CVE-2026-66858",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-66858"
},
{
"category": "external",
"summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-66858",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66858"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
"url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/6kl6g40tpl8zt3opd8fwn6bsgyddzhd5",
"url": "https://lists.apache.org/thread/6kl6g40tpl8zt3opd8fwn6bsgyddzhd5"
}
],
"release_date": "2026-10-02T12:27:31.412000+00:00",
"remediations": [
{
"category": "vendor_fix",
"date": "2026-10-01T06:16:09+00:00",
"details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
"product_ids": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
],
"restart_required": {
"category": "none"
},
"url": "https://access.redhat.com/errata/RHSA-2026:74369"
}
],
"scores": [
{
"cvss_v3": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
}
],
"threats": [
{
"category": "impact",
"details": "Important"
}
],
"title": "thrift: Apache Thrift: Denial of Service via deeply nested unknown fields"
},
{
"cve": "CVE-2026-82458",
"cwe": {
"id": "CWE-770",
"name": "Allocation of Resources Without Limits or Throttling"
},
"discovery_date": "2026-10-02T11:41:23.724436+00:00",
"ids": [
{
"system_name": "Red Hat Bugzilla ID",
"text": "2545042"
}
],
"notes": [
{
"category": "description",
"text": "A flaw was found in Apache Thrift. Multiple language bindings fail to properly restrict memory allocation when processing input containing excessive size values. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted requests, consuming available memory and causing a Denial of Service (DoS).",
"title": "Vulnerability description"
},
{
"category": "summary",
"text": "thrift: thrift: Denial of Service via excessive memory allocation",
"title": "Vulnerability summary"
},
{
"category": "general",
"text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
"title": "CVSS score applicability"
}
],
"product_status": {
"fixed": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
},
"references": [
{
"category": "self",
"summary": "Canonical URL",
"url": "https://access.redhat.com/security/cve/CVE-2026-82458"
},
{
"category": "external",
"summary": "RHBZ#2545042",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545042"
},
{
"category": "external",
"summary": "https://www.cve.org/CVERecord?id=CVE-2026-82458",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-82458"
},
{
"category": "external",
"summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-82458",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82458"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
"url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/7xqf651pvjykw0xr9vw0ooz0bwx7wzy7",
"url": "https://lists.apache.org/thread/7xqf651pvjykw0xr9vw0ooz0bwx7wzy7"
}
],
"release_date": "2026-10-02T11:30:51.264000+00:00",
"remediations": [
{
"category": "vendor_fix",
"date": "2026-10-01T06:16:09+00:00",
"details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
"product_ids": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
],
"restart_required": {
"category": "none"
},
"url": "https://access.redhat.com/errata/RHSA-2026:74369"
}
],
"scores": [
{
"cvss_v3": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
}
],
"threats": [
{
"category": "impact",
"details": "Important"
}
],
"title": "thrift: thrift: Denial of Service via excessive memory allocation"
},
{
"cve": "CVE-2026-82459",
"cwe": {
"id": "CWE-787",
"name": "Out-of-bounds Write"
},
"discovery_date": "2026-10-02T11:41:06.160175+00:00",
"ids": [
{
"system_name": "Red Hat Bugzilla ID",
"text": "2545041"
}
],
"notes": [
{
"category": "description",
"text": "A flaw was found in Apache Thrift. A remote, unauthenticated attacker could cause a Denial of Service (DoS) by sending specially crafted network traffic to an affected application. Due to an integer underflow in the 32-bit C++ THeaderTransport component, processing this malformed data triggers an out-of-bounds memory write, leading to an application crash.",
"title": "Vulnerability description"
},
{
"category": "summary",
"text": "thrift: thrift: Denial of Service via integer underflow in THeaderTransport",
"title": "Vulnerability summary"
},
{
"category": "general",
"text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
"title": "CVSS score applicability"
}
],
"product_status": {
"fixed": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
},
"references": [
{
"category": "self",
"summary": "Canonical URL",
"url": "https://access.redhat.com/security/cve/CVE-2026-82459"
},
{
"category": "external",
"summary": "RHBZ#2545041",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545041"
},
{
"category": "external",
"summary": "https://www.cve.org/CVERecord?id=CVE-2026-82459",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-82459"
},
{
"category": "external",
"summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-82459",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82459"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
"url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/zf8ppfpl6nqhp53sxnz6osnjw93g9fw2",
"url": "https://lists.apache.org/thread/zf8ppfpl6nqhp53sxnz6osnjw93g9fw2"
}
],
"release_date": "2026-10-02T11:32:30.148000+00:00",
"remediations": [
{
"category": "vendor_fix",
"date": "2026-10-01T06:16:09+00:00",
"details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
"product_ids": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
],
"restart_required": {
"category": "none"
},
"url": "https://access.redhat.com/errata/RHSA-2026:74369"
}
],
"scores": [
{
"cvss_v3": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
}
],
"threats": [
{
"category": "impact",
"details": "Important"
}
],
"title": "thrift: thrift: Denial of Service via integer underflow in THeaderTransport"
},
{
"cve": "CVE-2026-83745",
"cwe": {
"id": "CWE-130",
"name": "Improper Handling of Length Parameter Inconsistency"
},
"discovery_date": "2026-10-02T12:24:50.036523+00:00",
"ids": [
{
"system_name": "Red Hat Bugzilla ID",
"text": "2545142"
}
],
"notes": [
{
"category": "description",
"text": "A flaw was found in Apache Thrift. A remote attacker can cause a Denial of Service (DoS) against the Node.js and D WebSocket server transports by sending a frame specifying an excessively large payload length. Because the server immediately allocates the declared amount of memory without verifying that the payload data has arrived, an attacker can rapidly exhaust system memory and crash the service.",
"title": "Vulnerability description"
},
{
"category": "summary",
"text": "thrift: thrift: Denial of Service via excessive memory allocation in WebSocket transport",
"title": "Vulnerability summary"
},
{
"category": "general",
"text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
"title": "CVSS score applicability"
}
],
"product_status": {
"fixed": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
},
"references": [
{
"category": "self",
"summary": "Canonical URL",
"url": "https://access.redhat.com/security/cve/CVE-2026-83745"
},
{
"category": "external",
"summary": "RHBZ#2545142",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545142"
},
{
"category": "external",
"summary": "https://www.cve.org/CVERecord?id=CVE-2026-83745",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-83745"
},
{
"category": "external",
"summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-83745",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83745"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
"url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/64y7f0b89mnq4xoqcn4h26to8kskolgc",
"url": "https://lists.apache.org/thread/64y7f0b89mnq4xoqcn4h26to8kskolgc"
}
],
"release_date": "2026-10-02T12:16:15.128000+00:00",
"remediations": [
{
"category": "vendor_fix",
"date": "2026-10-01T06:16:09+00:00",
"details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
"product_ids": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
],
"restart_required": {
"category": "none"
},
"url": "https://access.redhat.com/errata/RHSA-2026:74369"
}
],
"scores": [
{
"cvss_v3": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
}
],
"threats": [
{
"category": "impact",
"details": "Important"
}
],
"title": "thrift: thrift: Denial of Service via excessive memory allocation in WebSocket transport"
},
{
"cve": "CVE-2026-85086",
"cwe": {
"id": "CWE-295",
"name": "Improper Certificate Validation"
},
"discovery_date": "2026-10-02T11:52:29.698780+00:00",
"ids": [
{
"system_name": "Red Hat Bugzilla ID",
"text": "2545053"
}
],
"notes": [
{
"category": "description",
"text": "A flaw was found in Apache Thrift\u0027s Perl bindings. Due to insecure default settings and improper certificate validation, client connections fail to verify the authenticity of remote server certificates. An unauthenticated attacker positioned on the network could exploit this vulnerability to conduct a man-in-the-middle (MitM) attack, allowing them to eavesdrop on or alter transmitted data and resulting in information disclosure.",
"title": "Vulnerability description"
},
{
"category": "summary",
"text": "thrift: thrift: Information disclosure via improper certificate validation in Perl bindings",
"title": "Vulnerability summary"
},
{
"category": "general",
"text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
"title": "CVSS score applicability"
}
],
"product_status": {
"fixed": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
},
"references": [
{
"category": "self",
"summary": "Canonical URL",
"url": "https://access.redhat.com/security/cve/CVE-2026-85086"
},
{
"category": "external",
"summary": "RHBZ#2545053",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545053"
},
{
"category": "external",
"summary": "https://www.cve.org/CVERecord?id=CVE-2026-85086",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-85086"
},
{
"category": "external",
"summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-85086",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85086"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
"url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/c7f9g4027ok0gocyso2y84r2mhgc2xmy",
"url": "https://lists.apache.org/thread/c7f9g4027ok0gocyso2y84r2mhgc2xmy"
}
],
"release_date": "2026-10-02T11:34:00.954000+00:00",
"remediations": [
{
"category": "vendor_fix",
"date": "2026-10-01T06:16:09+00:00",
"details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
"product_ids": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
],
"restart_required": {
"category": "none"
},
"url": "https://access.redhat.com/errata/RHSA-2026:74369"
}
],
"scores": [
{
"cvss_v3": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.4,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
}
],
"threats": [
{
"category": "impact",
"details": "Important"
}
],
"title": "thrift: thrift: Information disclosure via improper certificate validation in Perl bindings"
},
{
"cve": "CVE-2026-85088",
"cwe": {
"id": "CWE-295",
"name": "Improper Certificate Validation"
},
"discovery_date": "2026-10-02T11:59:54.540051+00:00",
"ids": [
{
"system_name": "Red Hat Bugzilla ID",
"text": "2545088"
}
],
"notes": [
{
"category": "description",
"text": "A flaw was found in Apache Thrift. During Transport Layer Security (TLS) certificate validation, the client libraries improperly evaluate the certificate\u0027s Common Name (CN) when subject alternative name (SAN) entries do not match the target host. A network-positioned attacker possessing a trusted certificate matching the host\u0027s Common Name can exploit this vulnerability to impersonate the legitimate server. Successful exploitation allows the attacker to intercept or tamper with encrypted communications.",
"title": "Vulnerability description"
},
{
"category": "summary",
"text": "thrift: thrift: Man-in-the-middle attacks via improper certificate validation",
"title": "Vulnerability summary"
},
{
"category": "general",
"text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
"title": "CVSS score applicability"
}
],
"product_status": {
"fixed": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
},
"references": [
{
"category": "self",
"summary": "Canonical URL",
"url": "https://access.redhat.com/security/cve/CVE-2026-85088"
},
{
"category": "external",
"summary": "RHBZ#2545088",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545088"
},
{
"category": "external",
"summary": "https://www.cve.org/CVERecord?id=CVE-2026-85088",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-85088"
},
{
"category": "external",
"summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-85088",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85088"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
"url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/zcgm7lx6037lvgvn87rc1tj3p0zhv371",
"url": "https://lists.apache.org/thread/zcgm7lx6037lvgvn87rc1tj3p0zhv371"
}
],
"release_date": "2026-10-02T11:37:14.749000+00:00",
"remediations": [
{
"category": "vendor_fix",
"date": "2026-10-01T06:16:09+00:00",
"details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
"product_ids": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
],
"restart_required": {
"category": "none"
},
"url": "https://access.redhat.com/errata/RHSA-2026:74369"
}
],
"scores": [
{
"cvss_v3": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.4,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
}
],
"threats": [
{
"category": "impact",
"details": "Important"
}
],
"title": "thrift: thrift: Man-in-the-middle attacks via improper certificate validation"
},
{
"cve": "CVE-2026-85494",
"cwe": {
"id": "CWE-130",
"name": "Improper Handling of Length Parameter Inconsistency"
},
"discovery_date": "2026-10-02T10:54:18.453376+00:00",
"ids": [
{
"system_name": "Red Hat Bugzilla ID",
"text": "2545019"
}
],
"notes": [
{
"category": "description",
"text": "A flaw was found in Apache Thrift. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending specially crafted requests to applications utilizing affected language bindings. Flawed input parameter processing and resource allocation can trigger application crashes or excessive resource consumption, rendering the service unavailable.",
"title": "Vulnerability description"
},
{
"category": "summary",
"text": "thrift: thrift: Denial of Service via improper message handling in language bindings",
"title": "Vulnerability summary"
},
{
"category": "general",
"text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
"title": "CVSS score applicability"
}
],
"product_status": {
"fixed": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
},
"references": [
{
"category": "self",
"summary": "Canonical URL",
"url": "https://access.redhat.com/security/cve/CVE-2026-85494"
},
{
"category": "external",
"summary": "RHBZ#2545019",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545019"
},
{
"category": "external",
"summary": "https://www.cve.org/CVERecord?id=CVE-2026-85494",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-85494"
},
{
"category": "external",
"summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-85494",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85494"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
"url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/rm0m34gt6fh1flvt16wty559hfg191qr",
"url": "https://lists.apache.org/thread/rm0m34gt6fh1flvt16wty559hfg191qr"
}
],
"release_date": "2026-10-02T10:42:44.813000+00:00",
"remediations": [
{
"category": "vendor_fix",
"date": "2026-10-01T06:16:09+00:00",
"details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
"product_ids": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
],
"restart_required": {
"category": "none"
},
"url": "https://access.redhat.com/errata/RHSA-2026:74369"
}
],
"scores": [
{
"cvss_v3": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
}
],
"threats": [
{
"category": "impact",
"details": "Important"
}
],
"title": "thrift: thrift: Denial of Service via improper message handling in language bindings"
},
{
"cve": "CVE-2026-86535",
"cwe": {
"id": "CWE-835",
"name": "Loop with Unreachable Exit Condition (\u0027Infinite Loop\u0027)"
},
"discovery_date": "2026-10-02T12:13:50.425036+00:00",
"ids": [
{
"system_name": "Red Hat Bugzilla ID",
"text": "2545128"
}
],
"notes": [
{
"category": "description",
"text": "A flaw was found in Apache Thrift. A remote attacker can exploit this vulnerability by submitting specially crafted messages to applications using the Node.js bindings with TJSONProtocol. Successful exploitation can trigger an infinite loop or cause prototype pollution (unintended modification of shared object attributes), resulting in a Denial of Service (DoS).",
"title": "Vulnerability description"
},
{
"category": "summary",
"text": "thrift: thrift: Denial of Service via TJSONProtocol in Node.js bindings",
"title": "Vulnerability summary"
},
{
"category": "general",
"text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
"title": "CVSS score applicability"
}
],
"product_status": {
"fixed": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
},
"references": [
{
"category": "self",
"summary": "Canonical URL",
"url": "https://access.redhat.com/security/cve/CVE-2026-86535"
},
{
"category": "external",
"summary": "RHBZ#2545128",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545128"
},
{
"category": "external",
"summary": "https://www.cve.org/CVERecord?id=CVE-2026-86535",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-86535"
},
{
"category": "external",
"summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-86535",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86535"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
"url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/94cvvzzl0rh707bn2j4zt844v547508g",
"url": "https://lists.apache.org/thread/94cvvzzl0rh707bn2j4zt844v547508g"
}
],
"release_date": "2026-10-02T11:38:16.628000+00:00",
"remediations": [
{
"category": "vendor_fix",
"date": "2026-10-01T06:16:09+00:00",
"details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
"product_ids": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
],
"restart_required": {
"category": "none"
},
"url": "https://access.redhat.com/errata/RHSA-2026:74369"
}
],
"scores": [
{
"cvss_v3": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
}
],
"threats": [
{
"category": "impact",
"details": "Important"
}
],
"title": "thrift: thrift: Denial of Service via TJSONProtocol in Node.js bindings"
},
{
"cve": "CVE-2026-86537",
"cwe": {
"id": "CWE-835",
"name": "Loop with Unreachable Exit Condition (\u0027Infinite Loop\u0027)"
},
"discovery_date": "2026-10-02T12:08:46.104212+00:00",
"ids": [
{
"system_name": "Red Hat Bugzilla ID",
"text": "2545121"
}
],
"notes": [
{
"category": "description",
"text": "A flaw was found in Apache Thrift\u0027s D language bindings. A remote, unauthenticated attacker could cause a Denial of Service (DoS) by sending specially crafted input to an affected application. This input triggers an integer underflow or an unhandled exception, causing the process to enter an infinite loop or terminate unexpectedly.",
"title": "Vulnerability description"
},
{
"category": "summary",
"text": "thrift: thrift: Denial of Service via infinite loop in D language bindings",
"title": "Vulnerability summary"
},
{
"category": "general",
"text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
"title": "CVSS score applicability"
}
],
"product_status": {
"fixed": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
},
"references": [
{
"category": "self",
"summary": "Canonical URL",
"url": "https://access.redhat.com/security/cve/CVE-2026-86537"
},
{
"category": "external",
"summary": "RHBZ#2545121",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545121"
},
{
"category": "external",
"summary": "https://www.cve.org/CVERecord?id=CVE-2026-86537",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-86537"
},
{
"category": "external",
"summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-86537",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86537"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
"url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/k14jfr1xwc0vtmm2s7xro6lt7q4y6s7m",
"url": "https://lists.apache.org/thread/k14jfr1xwc0vtmm2s7xro6lt7q4y6s7m"
}
],
"release_date": "2026-10-02T11:40:51.704000+00:00",
"remediations": [
{
"category": "vendor_fix",
"date": "2026-10-01T06:16:09+00:00",
"details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
"product_ids": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
],
"restart_required": {
"category": "none"
},
"url": "https://access.redhat.com/errata/RHSA-2026:74369"
}
],
"scores": [
{
"cvss_v3": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
}
],
"threats": [
{
"category": "impact",
"details": "Important"
}
],
"title": "thrift: thrift: Denial of Service via infinite loop in D language bindings"
},
{
"cve": "CVE-2026-90440",
"cwe": {
"id": "CWE-248",
"name": "Uncaught Exception"
},
"discovery_date": "2026-10-02T11:54:45.756003+00:00",
"ids": [
{
"system_name": "Red Hat Bugzilla ID",
"text": "2545066"
}
],
"notes": [
{
"category": "description",
"text": "A flaw was found in Apache Thrift\u0027s D language implementation within the TNonblockingServer component. Due to improper handling of exceptional conditions and improper resource shutdown, an uncaught exception can occur during server operations. A remote, unauthenticated attacker could exploit this vulnerability to cause a Denial of Service (DoS) by terminating the server process.",
"title": "Vulnerability description"
},
{
"category": "summary",
"text": "thrift: thrift: Denial of Service via improper exception handling in TNonblockingServer",
"title": "Vulnerability summary"
},
{
"category": "general",
"text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
"title": "CVSS score applicability"
}
],
"product_status": {
"fixed": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
},
"references": [
{
"category": "self",
"summary": "Canonical URL",
"url": "https://access.redhat.com/security/cve/CVE-2026-90440"
},
{
"category": "external",
"summary": "RHBZ#2545066",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545066"
},
{
"category": "external",
"summary": "https://www.cve.org/CVERecord?id=CVE-2026-90440",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-90440"
},
{
"category": "external",
"summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-90440",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90440"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
"url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/s8fjltl6c1pkm7vg9v4qkr89b5b74jbg",
"url": "https://lists.apache.org/thread/s8fjltl6c1pkm7vg9v4qkr89b5b74jbg"
}
],
"release_date": "2026-10-02T11:44:11.636000+00:00",
"remediations": [
{
"category": "vendor_fix",
"date": "2026-10-01T06:16:09+00:00",
"details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
"product_ids": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
],
"restart_required": {
"category": "none"
},
"url": "https://access.redhat.com/errata/RHSA-2026:74369"
}
],
"scores": [
{
"cvss_v3": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
}
],
"threats": [
{
"category": "impact",
"details": "Important"
}
],
"title": "thrift: thrift: Denial of Service via improper exception handling in TNonblockingServer"
},
{
"cve": "CVE-2026-93925",
"cwe": {
"id": "CWE-787",
"name": "Out-of-bounds Write"
},
"discovery_date": "2026-10-02T10:31:47.430017+00:00",
"ids": [
{
"system_name": "Red Hat Bugzilla ID",
"text": "2545010"
}
],
"notes": [
{
"category": "description",
"text": "A flaw was found in Apache Thrift. An incorrect bitwise integer shift in the C++ THeaderProtocol implementation can cause a stack-based buffer overflow. A remote, unauthenticated attacker could exploit this vulnerability by sending specially crafted input, resulting in a Denial of Service (DoS) caused by an application crash.",
"title": "Vulnerability description"
},
{
"category": "summary",
"text": "thrift: thrift: Denial of Service via stack-based buffer overflow in THeaderProtocol",
"title": "Vulnerability summary"
},
{
"category": "general",
"text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
"title": "CVSS score applicability"
}
],
"product_status": {
"fixed": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
},
"references": [
{
"category": "self",
"summary": "Canonical URL",
"url": "https://access.redhat.com/security/cve/CVE-2026-93925"
},
{
"category": "external",
"summary": "RHBZ#2545010",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545010"
},
{
"category": "external",
"summary": "https://www.cve.org/CVERecord?id=CVE-2026-93925",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-93925"
},
{
"category": "external",
"summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-93925",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-93925"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
"url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/b4rrkrwoyqb9g7hk58d3fx09cbvp1tg9",
"url": "https://lists.apache.org/thread/b4rrkrwoyqb9g7hk58d3fx09cbvp1tg9"
}
],
"release_date": "2026-10-02T10:16:17.913000+00:00",
"remediations": [
{
"category": "vendor_fix",
"date": "2026-10-01T06:16:09+00:00",
"details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
"product_ids": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
],
"restart_required": {
"category": "none"
},
"url": "https://access.redhat.com/errata/RHSA-2026:74369"
}
],
"scores": [
{
"cvss_v3": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
}
],
"threats": [
{
"category": "impact",
"details": "Important"
}
],
"title": "thrift: thrift: Denial of Service via stack-based buffer overflow in THeaderProtocol"
},
{
"cve": "CVE-2026-93926",
"cwe": {
"id": "CWE-772",
"name": "Missing Release of Resource after Effective Lifetime"
},
"discovery_date": "2026-10-02T10:31:33.640474+00:00",
"ids": [
{
"system_name": "Red Hat Bugzilla ID",
"text": "2545008"
}
],
"notes": [
{
"category": "description",
"text": "A flaw was found in Apache Thrift\u0027s THeaderTransport component. Due to a failure to release allocated memory and system resources after their operational lifetime, a remote attacker can exploit this vulnerability by sending network traffic that repeatedly consumes resources. This issue can cause system memory exhaustion, leading to a Denial of Service (DoS).",
"title": "Vulnerability description"
},
{
"category": "summary",
"text": "thrift: thrift: Denial of Service via memory leak in THeaderTransport",
"title": "Vulnerability summary"
}
],
"product_status": {
"fixed": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
},
"references": [
{
"category": "self",
"summary": "Canonical URL",
"url": "https://access.redhat.com/security/cve/CVE-2026-93926"
},
{
"category": "external",
"summary": "RHBZ#2545008",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545008"
},
{
"category": "external",
"summary": "https://www.cve.org/CVERecord?id=CVE-2026-93926",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-93926"
},
{
"category": "external",
"summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-93926",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-93926"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
"url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/9353rb8mpoq4ltff88h1j2y3hfy6blgb",
"url": "https://lists.apache.org/thread/9353rb8mpoq4ltff88h1j2y3hfy6blgb"
}
],
"release_date": "2026-10-02T10:13:55.957000+00:00",
"remediations": [
{
"category": "vendor_fix",
"date": "2026-10-01T06:16:09+00:00",
"details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
"product_ids": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
],
"restart_required": {
"category": "none"
},
"url": "https://access.redhat.com/errata/RHSA-2026:74369"
}
],
"threats": [
{
"category": "impact",
"details": "Important"
}
],
"title": "thrift: thrift: Denial of Service via memory leak in THeaderTransport"
},
{
"cve": "CVE-2026-94633",
"cwe": {
"id": "CWE-770",
"name": "Allocation of Resources Without Limits or Throttling"
},
"discovery_date": "2026-10-02T10:32:20.890715+00:00",
"ids": [
{
"system_name": "Red Hat Bugzilla ID",
"text": "2545011"
}
],
"notes": [
{
"category": "description",
"text": "A flaw was found in Apache Thrift\u0027s Dart bindings. An unauthenticated remote attacker can exploit this vulnerability by sending input containing inconsistent length parameters, triggering excessive memory allocation. This can lead to system memory exhaustion, resulting in a Denial of Service (DoS) condition.",
"title": "Vulnerability description"
},
{
"category": "summary",
"text": "thrift: thrift: Denial of Service via excessive memory allocation in Dart bindings",
"title": "Vulnerability summary"
},
{
"category": "general",
"text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
"title": "CVSS score applicability"
}
],
"product_status": {
"fixed": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
},
"references": [
{
"category": "self",
"summary": "Canonical URL",
"url": "https://access.redhat.com/security/cve/CVE-2026-94633"
},
{
"category": "external",
"summary": "RHBZ#2545011",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545011"
},
{
"category": "external",
"summary": "https://www.cve.org/CVERecord?id=CVE-2026-94633",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-94633"
},
{
"category": "external",
"summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-94633",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-94633"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
"url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/cxkbblyht7988p2o6yvnmd6536qmt88k",
"url": "https://lists.apache.org/thread/cxkbblyht7988p2o6yvnmd6536qmt88k"
}
],
"release_date": "2026-10-02T10:13:00.027000+00:00",
"remediations": [
{
"category": "vendor_fix",
"date": "2026-10-01T06:16:09+00:00",
"details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
"product_ids": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
],
"restart_required": {
"category": "none"
},
"url": "https://access.redhat.com/errata/RHSA-2026:74369"
}
],
"scores": [
{
"cvss_v3": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
}
],
"threats": [
{
"category": "impact",
"details": "Important"
}
],
"title": "thrift: thrift: Denial of Service via excessive memory allocation in Dart bindings"
},
{
"cve": "CVE-2026-94635",
"cwe": {
"id": "CWE-130",
"name": "Improper Handling of Length Parameter Inconsistency"
},
"discovery_date": "2026-10-02T09:32:01.870379+00:00",
"ids": [
{
"system_name": "Red Hat Bugzilla ID",
"text": "2544989"
}
],
"notes": [
{
"category": "description",
"text": "A flaw was found in the Apache Thrift Lua bindings. A remote attacker could exploit this vulnerability by sending requests containing inconsistent length parameters, triggering excessive resource allocation without proper limits. This issue can exhaust available system memory or processing capacity, resulting in a Denial of Service (DoS).",
"title": "Vulnerability description"
},
{
"category": "summary",
"text": "thrift: thrift: Denial of Service via improper length parameter handling in Lua bindings",
"title": "Vulnerability summary"
},
{
"category": "general",
"text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
"title": "CVSS score applicability"
}
],
"product_status": {
"fixed": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
},
"references": [
{
"category": "self",
"summary": "Canonical URL",
"url": "https://access.redhat.com/security/cve/CVE-2026-94635"
},
{
"category": "external",
"summary": "RHBZ#2544989",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2544989"
},
{
"category": "external",
"summary": "https://www.cve.org/CVERecord?id=CVE-2026-94635",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-94635"
},
{
"category": "external",
"summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-94635",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-94635"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
"url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/ow8994gb5g8ssmmbkbl48xqb0tpvqyr3",
"url": "https://lists.apache.org/thread/ow8994gb5g8ssmmbkbl48xqb0tpvqyr3"
}
],
"release_date": "2026-10-02T09:07:56.691000+00:00",
"remediations": [
{
"category": "vendor_fix",
"date": "2026-10-01T06:16:09+00:00",
"details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
"product_ids": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
],
"restart_required": {
"category": "none"
},
"url": "https://access.redhat.com/errata/RHSA-2026:74369"
}
],
"scores": [
{
"cvss_v3": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
}
],
"threats": [
{
"category": "impact",
"details": "Important"
}
],
"title": "thrift: thrift: Denial of Service via improper length parameter handling in Lua bindings"
},
{
"cve": "CVE-2026-94638",
"cwe": {
"id": "CWE-770",
"name": "Allocation of Resources Without Limits or Throttling"
},
"discovery_date": "2026-10-02T12:40:39.685068+00:00",
"ids": [
{
"system_name": "Red Hat Bugzilla ID",
"text": "2545160"
}
],
"notes": [
{
"category": "description",
"text": "A flaw was found in the Apache Thrift PHP bindings. Due to a lack of limits or throttling on resource allocation, a remote attacker can send crafted requests that consume excessive system resources. This issue can lead to a Denial of Service (DoS) for the affected service.",
"title": "Vulnerability description"
},
{
"category": "summary",
"text": "thrift: Apache Thrift: Denial of Service via uncontrolled resource allocation in PHP bindings",
"title": "Vulnerability summary"
},
{
"category": "general",
"text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
"title": "CVSS score applicability"
}
],
"product_status": {
"fixed": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
},
"references": [
{
"category": "self",
"summary": "Canonical URL",
"url": "https://access.redhat.com/security/cve/CVE-2026-94638"
},
{
"category": "external",
"summary": "RHBZ#2545160",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545160"
},
{
"category": "external",
"summary": "https://www.cve.org/CVERecord?id=CVE-2026-94638",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-94638"
},
{
"category": "external",
"summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-94638",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-94638"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
"url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/v60w786pqr7njzz9425grby8yjrgmbsj",
"url": "https://lists.apache.org/thread/v60w786pqr7njzz9425grby8yjrgmbsj"
}
],
"release_date": "2026-10-02T11:49:43.765000+00:00",
"remediations": [
{
"category": "vendor_fix",
"date": "2026-10-01T06:16:09+00:00",
"details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
"product_ids": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
],
"restart_required": {
"category": "none"
},
"url": "https://access.redhat.com/errata/RHSA-2026:74369"
}
],
"scores": [
{
"cvss_v3": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"products": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
}
],
"threats": [
{
"category": "impact",
"details": "Moderate"
}
],
"title": "thrift: Apache Thrift: Denial of Service via uncontrolled resource allocation in PHP bindings"
},
{
"cve": "CVE-2026-94646",
"cwe": {
"id": "CWE-915",
"name": "Improperly Controlled Modification of Dynamically-Determined Object Attributes"
},
"discovery_date": "2026-10-02T12:23:11.847024+00:00",
"ids": [
{
"system_name": "Red Hat Bugzilla ID",
"text": "2545138"
}
],
"notes": [
{
"category": "description",
"text": "A flaw was found in Apache Thrift\u0027s Node.js bindings. Due to improper input validation and prototype pollution\u2014a condition where base JavaScript object properties can be modified\u2014the application fails to safely process incoming data. A remote attacker can exploit this vulnerability by sending specially crafted input to trigger an uncaught exception, causing the service to crash and resulting in a Denial of Service (DoS).",
"title": "Vulnerability description"
},
{
"category": "summary",
"text": "thrift: thrift: Denial of Service via prototype pollution in Node.js bindings",
"title": "Vulnerability summary"
},
{
"category": "general",
"text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
"title": "CVSS score applicability"
}
],
"product_status": {
"fixed": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
},
"references": [
{
"category": "self",
"summary": "Canonical URL",
"url": "https://access.redhat.com/security/cve/CVE-2026-94646"
},
{
"category": "external",
"summary": "RHBZ#2545138",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545138"
},
{
"category": "external",
"summary": "https://www.cve.org/CVERecord?id=CVE-2026-94646",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-94646"
},
{
"category": "external",
"summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-94646",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-94646"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
"url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/5hjh0gz8wf6bo7ydxjpqj92m42hwmfo8",
"url": "https://lists.apache.org/thread/5hjh0gz8wf6bo7ydxjpqj92m42hwmfo8"
}
],
"release_date": "2026-10-02T11:52:21.192000+00:00",
"remediations": [
{
"category": "vendor_fix",
"date": "2026-10-01T06:16:09+00:00",
"details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
"product_ids": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
],
"restart_required": {
"category": "none"
},
"url": "https://access.redhat.com/errata/RHSA-2026:74369"
}
],
"scores": [
{
"cvss_v3": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
}
],
"threats": [
{
"category": "impact",
"details": "Important"
}
],
"title": "thrift: thrift: Denial of Service via prototype pollution in Node.js bindings"
},
{
"cve": "CVE-2026-94650",
"cwe": {
"id": "CWE-770",
"name": "Allocation of Resources Without Limits or Throttling"
},
"discovery_date": "2026-10-02T11:01:28.298445+00:00",
"ids": [
{
"system_name": "Red Hat Bugzilla ID",
"text": "2545020"
}
],
"notes": [
{
"category": "description",
"text": "A flaw was found in Apache Thrift. An uncontrolled recursion vulnerability in the C (GLib) library bindings allows a remote, unauthenticated attacker to send specially crafted input to an affected application. Processing this input triggers excessive nested function calls that exhaust stack memory, causing an application crash and resulting in a Denial of Service (DoS).",
"title": "Vulnerability description"
},
{
"category": "summary",
"text": "thrift: thrift: Denial of Service via uncontrolled recursion in C GLib bindings",
"title": "Vulnerability summary"
}
],
"product_status": {
"fixed": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
},
"references": [
{
"category": "self",
"summary": "Canonical URL",
"url": "https://access.redhat.com/security/cve/CVE-2026-94650"
},
{
"category": "external",
"summary": "RHBZ#2545020",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545020"
},
{
"category": "external",
"summary": "https://www.cve.org/CVERecord?id=CVE-2026-94650",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-94650"
},
{
"category": "external",
"summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-94650",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-94650"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
"url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/poskkt3p754b2f293g63934hw160o86j",
"url": "https://lists.apache.org/thread/poskkt3p754b2f293g63934hw160o86j"
}
],
"release_date": "2026-10-02T10:49:37.521000+00:00",
"remediations": [
{
"category": "vendor_fix",
"date": "2026-10-01T06:16:09+00:00",
"details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
"product_ids": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
],
"restart_required": {
"category": "none"
},
"url": "https://access.redhat.com/errata/RHSA-2026:74369"
}
],
"threats": [
{
"category": "impact",
"details": "Important"
}
],
"title": "thrift: thrift: Denial of Service via uncontrolled recursion in C GLib bindings"
},
{
"cve": "CVE-2026-94657",
"cwe": {
"id": "CWE-770",
"name": "Allocation of Resources Without Limits or Throttling"
},
"discovery_date": "2026-10-02T12:27:57.067572+00:00",
"ids": [
{
"system_name": "Red Hat Bugzilla ID",
"text": "2545148"
}
],
"notes": [
{
"category": "description",
"text": "A flaw was found in Apache Thrift. A remote attacker could exploit improper resource allocation controls in the JavaME bindings to cause a Denial of Service (DoS). By sending requests that trigger unbounded resource consumption, an attacker can exhaust system resources and make the service unavailable.",
"title": "Vulnerability description"
},
{
"category": "summary",
"text": "thrift: thrift: Denial of Service via improper resource allocation in JavaME bindings",
"title": "Vulnerability summary"
}
],
"product_status": {
"fixed": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
},
"references": [
{
"category": "self",
"summary": "Canonical URL",
"url": "https://access.redhat.com/security/cve/CVE-2026-94657"
},
{
"category": "external",
"summary": "RHBZ#2545148",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545148"
},
{
"category": "external",
"summary": "https://www.cve.org/CVERecord?id=CVE-2026-94657",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-94657"
},
{
"category": "external",
"summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-94657",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-94657"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
"url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/lpcmo2xjfyfww474xdyyfypkqthk9s14",
"url": "https://lists.apache.org/thread/lpcmo2xjfyfww474xdyyfypkqthk9s14"
}
],
"release_date": "2026-10-02T12:01:36.606000+00:00",
"remediations": [
{
"category": "vendor_fix",
"date": "2026-10-01T06:16:09+00:00",
"details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
"product_ids": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
],
"restart_required": {
"category": "none"
},
"url": "https://access.redhat.com/errata/RHSA-2026:74369"
}
],
"threats": [
{
"category": "impact",
"details": "Important"
}
],
"title": "thrift: thrift: Denial of Service via improper resource allocation in JavaME bindings"
},
{
"cve": "CVE-2026-96277",
"cwe": {
"id": "CWE-248",
"name": "Uncaught Exception"
},
"discovery_date": "2026-10-02T12:39:08.569139+00:00",
"ids": [
{
"system_name": "Red Hat Bugzilla ID",
"text": "2545159"
}
],
"notes": [
{
"category": "description",
"text": "A flaw was found in the Apache Thrift Ruby bindings. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) due to improper handling of exceptional conditions. By triggering an uncaught exception, an attacker can crash the service and disrupt availability.",
"title": "Vulnerability description"
},
{
"category": "summary",
"text": "thrift: thrift: Denial of Service via uncaught exception in Ruby bindings",
"title": "Vulnerability summary"
}
],
"product_status": {
"fixed": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
},
"references": [
{
"category": "self",
"summary": "Canonical URL",
"url": "https://access.redhat.com/security/cve/CVE-2026-96277"
},
{
"category": "external",
"summary": "RHBZ#2545159",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545159"
},
{
"category": "external",
"summary": "https://www.cve.org/CVERecord?id=CVE-2026-96277",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-96277"
},
{
"category": "external",
"summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-96277",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-96277"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
"url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/k1t5r9sz7k5tn57cnf5khw2ywlxv6098",
"url": "https://lists.apache.org/thread/k1t5r9sz7k5tn57cnf5khw2ywlxv6098"
}
],
"release_date": "2026-10-02T12:03:23.964000+00:00",
"remediations": [
{
"category": "vendor_fix",
"date": "2026-10-01T06:16:09+00:00",
"details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
"product_ids": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
],
"restart_required": {
"category": "none"
},
"url": "https://access.redhat.com/errata/RHSA-2026:74369"
}
],
"threats": [
{
"category": "impact",
"details": "Important"
}
],
"title": "thrift: thrift: Denial of Service via uncaught exception in Ruby bindings"
},
{
"cve": "CVE-2026-96292",
"cwe": {
"id": "CWE-1333",
"name": "Inefficient Regular Expression Complexity"
},
"discovery_date": "2026-10-02T11:30:57.884653+00:00",
"ids": [
{
"system_name": "Red Hat Bugzilla ID",
"text": "2545035"
}
],
"notes": [
{
"category": "description",
"text": "A flaw was found in Apache Thrift\u0027s Lua bindings. A remote attacker could exploit this vulnerability by sending specially crafted input that triggers inefficient regular expression processing. This can cause excessive resource consumption, resulting in a Denial of Service (DoS) on the affected service.",
"title": "Vulnerability description"
},
{
"category": "summary",
"text": "thrift: thrift: Denial of Service via inefficient regular expression evaluation in Lua bindings",
"title": "Vulnerability summary"
}
],
"product_status": {
"fixed": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
]
},
"references": [
{
"category": "self",
"summary": "Canonical URL",
"url": "https://access.redhat.com/security/cve/CVE-2026-96292"
},
{
"category": "external",
"summary": "RHBZ#2545035",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2545035"
},
{
"category": "external",
"summary": "https://www.cve.org/CVERecord?id=CVE-2026-96292",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-96292"
},
{
"category": "external",
"summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-96292",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-96292"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1",
"url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/3wmvtvv56rky5wtszn4zr8w12kg928qn",
"url": "https://lists.apache.org/thread/3wmvtvv56rky5wtszn4zr8w12kg928qn"
}
],
"release_date": "2026-10-02T11:11:33.256000+00:00",
"remediations": [
{
"category": "vendor_fix",
"date": "2026-10-01T06:16:09+00:00",
"details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
"product_ids": [
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-aarch64-rpms",
"Red Hat Hardened Images:perl-thrift-0:0.25.0-0.1.hum1@noarch@public-hummingbird-x86_64-rpms",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:python3-thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@src",
"Red Hat Hardened Images:thrift-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-devel-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-glib-0:0.25.0-0.1.hum1@x86_64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@aarch64",
"Red Hat Hardened Images:thrift-qt-0:0.25.0-0.1.hum1@x86_64"
],
"restart_required": {
"category": "none"
},
"url": "https://access.redhat.com/errata/RHSA-2026:74369"
}
],
"threats": [
{
"category": "impact",
"details": "Important"
}
],
"title": "thrift: thrift: Denial of Service via inefficient regular expression evaluation in Lua bindings"
}
]
}
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.