Common Vulnerabilities and Exposures (CVE)

CVE-2026-66331

Oct 3, 2026 15:52:56 UTC

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Delphi bindings buffered transport. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes t...

CVE-2026-66055

Oct 3, 2026 15:52:56 UTC

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift C++, Java, Go, netstd, Python and Delphi bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0...

CVE-2026-63772

Oct 3, 2026 15:52:56 UTC

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift go bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-61374

Oct 3, 2026 15:52:56 UTC

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-66054

Oct 3, 2026 15:52:56 UTC

Allocation of Resources Without Limits or Throttling, Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended...

CVE-2026-101104

Oct 3, 2026 15:52:56 UTC

The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to manipulate the configurations of devices they do not own. This vulnerability enables attackers to perform unauthorized ac...

CVE-2026-104910

Oct 3, 2026 15:52:56 UTC

MISP contains an authorization bypass in the related events listing functionality. When a user requests the list of events correlated to a given event, the system retrieved related event metadata directly from the correlation table without ...

CVE-2026-96613

Oct 3, 2026 15:52:55 UTC

The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to access the complete device shadow of any device by specifying its device ID. This vulnerability exposes sensitive informa...

CVE-2026-104912

Oct 3, 2026 15:52:55 UTC

MISP contains an authorization flaw in its correlation handling during attribute searches. When a user performs an attribute search that triggers correlation lookups, the system authorized access to correlated attributes and events based on...

CVE-2026-103648

Oct 3, 2026 15:52:55 UTC

Path traversal in image-downloader 4.3.0 allows an attacker who can control the download URL to cause downloaded response data to be written outside the configured destination directory.

CVE-2026-12392

Oct 3, 2026 15:52:55 UTC

An information exposure vulnerability in Canonical MAAS prior to versions 3.4.10, 3.5.14, 3.6.5, 3.7.3, and 3.8.0 allows an unauthenticated attacker to retrieve the RPC secret in plaintext via the vendor data metadata endpoint. If a target ...

CVE-2026-75937

Oct 3, 2026 15:52:55 UTC

A specially crafted HTTP POST request to the web administration interface allows an unauthenticated attacker to execute arbitrary operating system commands with root privileges on the affected device. Disable the web server when not configu...

CVE-2026-104055

Oct 3, 2026 15:52:55 UTC

The postgresql-operator charm runs a Prometheus postgres_exporter to collect database metrics using a dedicated "monitoring" PostgreSQL user. On database connection errors, the exporter writes the monitoring user's password in cleartext to ...

CVE-2026-93474

Oct 3, 2026 15:52:54 UTC

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

CVE-2026-97212

Oct 3, 2026 15:52:54 UTC

The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulnerab...