{"success":true,"data":{"threats":[{"id":"57eb179a-6e66-40a5-add9-291967e26a1e","slug":"cve-2026-107392","externalId":"CVE-2026-107392","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107392 — music-metadata is a metadata parser for audio and video media files.","description":"music-metadata is a metadata parser for audio and video media files. Prior to 11.15.0, the DSF parser handles an unrecognized chunk by calling tokenizer.ignore without awaiting the returned promise and without first rejecting a chunk size smaller than the 12-byte chunk header. A crafted DSF input can produce a negative ignore length; with strtok3 10.3.5 or later, the resulting RangeError is detached from the parseBuffer promise and becomes an unhandled rejection under Node.js default behavior. The parse call can appear to resolve before the process crashes, bypassing per-parse try/catch handling. The demonstrated impact is availability loss only and requires the DSF parsing path. This issue is fixed in version 11.15.0.","cveId":"CVE-2026-107392","cvssScore":6.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":"npm","product":"music-metadata","affectedVersions":["pkg:npm/music-metadata < 11.15.0"],"cwes":["CWE-248","CWE-400"],"tags":["nvd","status:awaiting-analysis","osv","osv:ghsa-8j4c-6x6g-rq3j","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/Borewit/music-metadata/commit/e7fc27a96e789d41ece41fdac590fc7618274a41","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/pull/2700","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/releases/tag/v11.15.0","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/security/advisories/GHSA-8j4c-6x6g-rq3j","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-8j4c-6x6g-rq3j","type":"advisory","title":"OSV GHSA-8j4c-6x6g-rq3j"},{"url":"https://github.com/Borewit/music-metadata","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:33.707Z","addedAt":"2026-10-08T21:05:52.984Z","updatedAt":"2026-10-08T21:08:30.817Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107392","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107392","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-8J4C-6X6G-RQ3J"}]},{"id":"b1254390-ff69-4601-bfd4-96d2baac21b5","slug":"cve-2026-107382","externalId":"CVE-2026-107382","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107382 — MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases.","description":"MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. From 3.3.0 until 3.5.4, the zero-configuration TLS fingerprint-validation path calls Ed25519PasswordAuth.hash() through Authentication.validateFingerPrint, but Ed25519PasswordAuth.hash() references a seed identifier that is not in scope. Exposure requires a MariaDB server reached over TCP, TLS enabled with ssl: true or an ssl object whose rejectUnauthorized value is not false, a password set, no ssl.ca configured, and client_ed25519 negotiated as the authentication plugin. Under those conditions, a legitimate server, malicious server, or network attacker presenting a self-signed certificate can reach this path and cause a synchronous ReferenceError to escape the socket data handler. Under Node.js default uncaught-exception behavior, the client process terminates, causing denial of service. Configurations using a provided CA, rejectUnauthorized: false, another authentication plugin, or a Unix socket do not reach this vulnerable path. This issue is fixed in version 3.5.4.","cveId":"CVE-2026-107382","cvssScore":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":"npm","product":"mariadb","affectedVersions":["pkg:npm/mariadb >= 3.3.0, < 3.5.4"],"cwes":["CWE-248"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-cx2f-j9fh-8g68","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/784ca3d757194a05f202d84b0c762321e76a7915","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.5.4","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/security/advisories/GHSA-cx2f-j9fh-8g68","type":"other","title":"OSV web"},{"url":"https://hackerone.com/reports/3835450","type":"advisory","title":"security-advisories@github.com"},{"url":"https://jira.mariadb.org/browse/CONJS-356","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-cx2f-j9fh-8g68","type":"advisory","title":"OSV GHSA-cx2f-j9fh-8g68"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T19:17:00.590Z","addedAt":"2026-10-08T19:33:16.935Z","updatedAt":"2026-10-08T21:08:30.761Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107382","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107382","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-CX2F-J9FH-8G68"}]},{"id":"0303dc62-cd0e-421b-8d5c-1276e1803083","slug":"cve-2026-107214","externalId":"CVE-2026-107214","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107214 — Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets.","description":"Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, the decryption dispatch performs insufficient structural and parameter validation before standard and agile decryptors slice, index, allocate, and divide using attacker-controlled values. Decrypt passes attacker-controlled EncryptionInfo and EncryptedPackage data into standardDecrypt or agileDecrypt before validating the structures used by those routines. When a malformed OLE compound file with a version-valid EncryptionInfo stream is opened or passed to Decrypt, nine malformed-input classes reach unrecovered Go runtime panics instead of the documented error path, allowing an attacker to terminate the calling process. No fixed version is available as of this review.","cveId":"CVE-2026-107214","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":"Go","product":"github.com/xuri/excelize/v2","affectedVersions":["pkg:golang/github.com/xuri/excelize/v2 >= 2.3.1, < 2.11.1-0.20260915055537-22f76f9acb94"],"cwes":["CWE-248"],"tags":["nvd","status:received","osv","osv:ghsa-2j4c-ffch-9f23","ecosystem:go","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/qax-os/excelize/commit/22f76f9acb94b85b3eb9c4365ab4f750cebbc565","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/qax-os/excelize/pull/2395","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/qax-os/excelize/security/advisories/GHSA-2j4c-ffch-9f23","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://osv.dev/vulnerability/GHSA-2j4c-ffch-9f23","type":"advisory","title":"OSV GHSA-2j4c-ffch-9f23"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107214","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/qax-os/excelize","type":"vendor","title":"OSV package"}],"epssScore":0.00271,"epssPercentile":0.17748,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T18:17:19.040Z","addedAt":"2026-10-07T18:39:31.685Z","updatedAt":"2026-10-08T21:05:43.407Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107214","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107214","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-2J4C-FFCH-9F23"}]},{"id":"3c480fb4-fa4d-4eff-acc9-95db620c37e1","slug":"cve-2026-78243","externalId":"CVE-2026-78243","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-78243 — Apache YuniKorn 1.8.0 and later, if configured with the LDAP group resolver, crashes due to an out of bounds read processing group membership entri…","description":"Apache YuniKorn 1.8.0 and later, if configured with the LDAP group resolver, crashes due to an out of bounds read processing group membership entries.If the LDAP server returns a group membership entry, memberOf attribute, for a user specified in the pod the server crashes if a membership record does not start with \"CN=\".\n\n\n\n\nThis only affects install that have the non default LDAP group provider configured. \n\n\nUsers are recommended to upgrade to version 1.10.0, which fixes this issue.","cveId":"CVE-2026-78243","cvssScore":2.1,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:A/V:D/RE:H/U:Green","severity":"low","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-248"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread.html/yz51lpj6k8q2hz7x2gjdpcrk44hdn25v","type":"advisory","title":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/10/07/24","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"}],"epssScore":0.00288,"epssPercentile":0.19603,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T10:17:36.017Z","addedAt":"2026-10-07T10:39:38.897Z","updatedAt":"2026-10-07T18:39:30.853Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-78243","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-78243","note":"authoritative record"}]},{"id":"3c0e17d4-843f-4437-8c98-c0f05c7faa71","slug":"cve-2026-96399","externalId":"CVE-2026-96399","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-96399 — A repository's external issue tracker regular expression containing alternating capture groups could produce invalid slice indexes when Gitea rende…","description":"A repository's external issue tracker regular expression containing alternating capture groups could produce invalid slice indexes when Gitea rendered issue references, causing a runtime panic that terminated the Gitea process. A user who can edit a repository's external issue tracker settings could make any later rendering of matching content, such as viewing a README, crash the instance for all users.","cveId":"CVE-2026-96399","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-125","CWE-248"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.gitea.com/release-of-28.0.0/","type":"advisory","title":"88ee5874-cf24-4952-aea0-31affedb7ff2"},{"url":"https://github.com/go-gitea/gitea/pull/39354","type":"advisory","title":"88ee5874-cf24-4952-aea0-31affedb7ff2"},{"url":"https://github.com/go-gitea/gitea/releases/tag/v28.0.0","type":"advisory","title":"88ee5874-cf24-4952-aea0-31affedb7ff2"},{"url":"https://github.com/go-gitea/gitea/security/advisories/GHSA-mw6q-qj47-9g5q","type":"advisory","title":"88ee5874-cf24-4952-aea0-31affedb7ff2"}],"epssScore":0.0035,"epssPercentile":0.26599,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T20:17:35.270Z","addedAt":"2026-10-06T20:39:33.500Z","updatedAt":"2026-10-07T22:39:36.267Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-96399","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-96399","note":"authoritative record"}]},{"id":"666acd51-66a0-4d61-a03d-6c3e2b8062ea","slug":"cve-2026-102413","externalId":"CVE-2026-102413","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-102413 — Uncaught Exception (CWE-248) in Elastic Endpoint can lead to denial of service via a specially crafted file name.","description":"Uncaught Exception (CWE-248) in Elastic Endpoint can lead to denial of service via a specially crafted file name. When Elastic Defend's Elastic Endpoint component processes a file name under certain system locale configurations (including Chinese, Japanese, and Korean locales) on Windows, an unhandled exception can occur during file-path handling. This causes the Elastic Endpoint process to crash and restart repeatedly, which can degrade or disable Elastic Defend's real-time malware prevention and behavioral detection capabilities on the affected host for as long as the condition persists.","cveId":"CVE-2026-102413","cvssScore":6.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-248"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://discuss.elastic.co/t/elastic-agent-endpoint-8-19-22-9-4-8-and-9-5-5-security-update-esa-2026-194/390868","type":"advisory","title":"security@elastic.co"}],"epssScore":0.00131,"epssPercentile":0.02343,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T20:17:13.463Z","addedAt":"2026-10-06T20:39:32.859Z","updatedAt":"2026-10-07T14:39:34.016Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102413","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-102413","note":"authoritative record"}]},{"id":"42e87940-a70e-4835-90a8-810a6d950eba","slug":"cve-2026-106122","externalId":"CVE-2026-106122","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106122 — The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes.","description":"The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.36.0, ValueReader.readShortstr decodes malformed UTF-8 bytes into replacement characters that can re-encode beyond the AMQP shortstr limit enforced by ValueWriter.writeShortstr. An attacker who can submit an RPC message with a malformed echoed property can cause reply publication in RpcServer.mainloop() or tutorial-style consumers to throw an unchecked exception before acknowledgement. The broker requeues the message, allowing the same message to disable replacement consumers until the queue is purged. This issue is fixed in version 5.36.0.","cveId":"CVE-2026-106122","cvssScore":6,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":"Maven","product":"com.rabbitmq:amqp-client","affectedVersions":["pkg:maven/com.rabbitmq/amqp-client < 5.36.0"],"cwes":["CWE-172","CWE-248"],"tags":["nvd","status:awaiting-analysis","osv","osv:ghsa-7822-rcf6-97fx","ecosystem:maven"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/rabbitmq/rabbitmq-java-client/commit/b8bd750fa8c90690e859b18d6343b34421309020","type":"other","title":"OSV web"},{"url":"https://github.com/rabbitmq/rabbitmq-java-client/pull/2065","type":"other","title":"OSV web"},{"url":"https://github.com/rabbitmq/rabbitmq-java-client/releases/tag/v5.36.0","type":"other","title":"OSV web"},{"url":"https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-7822-rcf6-97fx","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-7822-rcf6-97fx","type":"advisory","title":"OSV GHSA-7822-rcf6-97fx"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106122","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/rabbitmq/rabbitmq-java-client","type":"vendor","title":"OSV package"}],"epssScore":0.00409,"epssPercentile":0.33072,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:17:43.467Z","addedAt":"2026-10-06T20:39:30.430Z","updatedAt":"2026-10-08T00:42:50.051Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106122","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106122","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-7822-RCF6-97FX"}]},{"id":"4677f270-48c6-4ad8-aad2-9024791ef1db","slug":"cve-2026-105757","externalId":"CVE-2026-105757","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105757 — vLLM is an inference and serving engine for large language models.","description":"vLLM is an inference and serving engine for large language models. Prior to 0.30.0, structured-output request failures can escape request-scoped validation and reach the EngineCore fatal-error path. A per-request backend mismatch can re-raise a grammar compilation exception, padding produced by the ngram_gpu speculative-decoding mode can pass a negative token to guidance validation, and the Rust frontend can admit empty structured-output values that the Python frontend rejects, allowing ordinary constrained-generation requests to terminate the shared engine. This issue is fixed in version 0.30.0.","cveId":"CVE-2026-105757","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":"vllm","product":"vllm","affectedVersions":["pkg:pypi/vllm < 0.30.0","< 0.30.0"],"cwes":["CWE-20","CWE-248","CWE-755"],"tags":["nvd","status:received","osv","osv:ghsa-85xf-c7hm-whqw","ecosystem:pypi","status:undergoing-analysis","status:analyzed","osv:pysec-2026-4199"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/vllm-project/vllm/commit/c55e15a44ec4127832d4a86928a356fdd9e68dbd","https://github.com/vllm-project/vllm/pull/51450"],"references":[{"url":"https://github.com/vllm-project/vllm/commit/c55e15a44ec4127832d4a86928a356fdd9e68dbd","type":"patch","title":"OSV fix"},{"url":"https://github.com/vllm-project/vllm/pull/51450","type":"patch","title":"OSV fix"},{"url":"https://github.com/vllm-project/vllm/releases/tag/v0.30.0","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-85xf-c7hm-whqw","type":"advisory","title":"OSV advisory"},{"url":"https://osv.dev/vulnerability/GHSA-85xf-c7hm-whqw","type":"advisory","title":"OSV GHSA-85xf-c7hm-whqw"},{"url":"https://github.com/vllm-project/vllm","type":"vendor","title":"OSV package"},{"url":"https://osv.dev/vulnerability/PYSEC-2026-4199","type":"advisory","title":"OSV PYSEC-2026-4199"}],"epssScore":0.00314,"epssPercentile":0.22284,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T23:17:02.467Z","addedAt":"2026-10-05T23:50:40.493Z","updatedAt":"2026-10-08T12:42:40.338Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105757","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105757","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-85XF-C7HM-WHQW"}]},{"id":"3cc2bf3c-1ca2-4652-9eca-5fa3f2180186","slug":"cve-2026-105756","externalId":"CVE-2026-105756","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105756 — vLLM is an inference and serving engine for large language models.","description":"vLLM is an inference and serving engine for large language models. Prior to 0.30.0, OpenAI-compatible request models accept a non-empty cache_salt value without enforcing the character and length restrictions required by the IPCCacheServerKey consumer in LMCache-MP. On deployments using the LMCache-MP connector, a salt that contains a forbidden character or exceeds the permitted length can raise an uncaught ValueError during scheduler cache lookup, causing EngineCore to terminate and denying service to all concurrent users. This issue is fixed in version 0.30.0.","cveId":"CVE-2026-105756","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":"vllm","product":"vllm","affectedVersions":["pkg:pypi/vllm < 0.30.0","< 0.30.0"],"cwes":["CWE-20","CWE-248"],"tags":["nvd","status:received","osv","osv:ghsa-2823-qmq8-rwvj","ecosystem:pypi","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/vllm-project/vllm/commit/e962733e08d10f7ca65dac4df99e116460b8b174","https://github.com/vllm-project/vllm/pull/51444"],"references":[{"url":"https://github.com/vllm-project/vllm/commit/e962733e08d10f7ca65dac4df99e116460b8b174","type":"patch","title":"Patch"},{"url":"https://github.com/vllm-project/vllm/pull/51444","type":"patch","title":"Issue Tracking"},{"url":"https://github.com/vllm-project/vllm/releases/tag/v0.30.0","type":"advisory","title":"Release Notes"},{"url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-2823-qmq8-rwvj","type":"vendor","title":"Mitigation"},{"url":"https://osv.dev/vulnerability/GHSA-2823-qmq8-rwvj","type":"advisory","title":"OSV GHSA-2823-qmq8-rwvj"},{"url":"https://github.com/vllm-project/vllm","type":"vendor","title":"OSV package"}],"epssScore":0.00314,"epssPercentile":0.22285,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T23:17:02.317Z","addedAt":"2026-10-05T23:50:40.489Z","updatedAt":"2026-10-08T02:39:29.694Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105756","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105756","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-2823-QMQ8-RWVJ"}]},{"id":"65f86b84-6052-405e-beb6-ec688c81a0a5","slug":"cve-2026-58859","externalId":"CVE-2026-58859","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-58859 — In multiple places, there is a possible  denial of service due to an uncaught exception.","description":"In multiple places, there is a possible  denial of service due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.","cveId":"CVE-2026-58859","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"google","product":"android","affectedVersions":["17.0"],"cwes":["CWE-248"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://source.android.com/docs/security/bulletin/2026/2026-10-01"],"references":[{"url":"https://source.android.com/docs/security/bulletin/2026/2026-10-01","type":"patch","title":"Patch"}],"epssScore":0.00068,"epssPercentile":0.00027,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T19:17:25.073Z","addedAt":"2026-10-05T19:50:42.974Z","updatedAt":"2026-10-07T16:39:30.459Z","epssUpdatedAt":"2026-10-07T12:00:27.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58859","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-58859","note":"authoritative record"}]},{"id":"68e02019-db7f-4e8b-9342-64003b09ff32","slug":"cve-2026-96286","externalId":"CVE-2026-96286","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-96286 — Uncaught exception vulnerability in Apache Thrift Perl bindings.","description":"Uncaught exception vulnerability in Apache Thrift Perl bindings.\n\n\n\nThis issue affects Apache Thrift: before 0.25.0.\n\n\n\nUsers are recommended to upgrade to version 0.25.0, which fixes the issue.","cveId":"CVE-2026-96286","cvssScore":8.2,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-248"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1","type":"advisory","title":"security@apache.org"},{"url":"https://lists.apache.org/thread/o5386v7ytbbjv9sx7dbszw46ypod5yd9","type":"advisory","title":"security@apache.org"}],"epssScore":0.00426,"epssPercentile":0.34846,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T13:18:05.247Z","addedAt":"2026-10-02T13:50:41.011Z","updatedAt":"2026-10-02T15:50:41.152Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-96286","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-96286","note":"authoritative record"}]},{"id":"7d5ed28d-f959-4980-9f9a-ffa129236a01","slug":"cve-2026-96277","externalId":"CVE-2026-96277","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-96277 — Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift Ruby bindings.","description":"Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift Ruby bindings.\n\n\n\nThis issue affects Apache Thrift: before 0.25.0.\n\n\n\nUsers are recommended to upgrade to version 0.25.0, which fixes the issue.","cveId":"CVE-2026-96277","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-248","CWE-755"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1","type":"advisory","title":"security@apache.org"},{"url":"https://lists.apache.org/thread/k1t5r9sz7k5tn57cnf5khw2ywlxv6098","type":"advisory","title":"security@apache.org"}],"epssScore":0.00426,"epssPercentile":0.34847,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T13:18:05.010Z","addedAt":"2026-10-02T13:50:41.006Z","updatedAt":"2026-10-02T15:50:41.146Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-96277","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-96277","note":"authoritative record"}]},{"id":"ac58f9f0-4d91-498b-8f98-7beb4c547958","slug":"cve-2026-96294","externalId":"CVE-2026-96294","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-96294 — Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift NodeJS bindings.","description":"Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift NodeJS bindings.\n\n\n\nThis issue affects Apache Thrift: before 0.25.0.\n\n\n\nUsers are recommended to upgrade to version 0.25.0, which fixes the issue.","cveId":"CVE-2026-96294","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-248","CWE-755"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1","type":"advisory","title":"security@apache.org"},{"url":"https://lists.apache.org/thread/52gwhsy947hj9qhgn0dql726z1q927g4","type":"advisory","title":"security@apache.org"}],"epssScore":0.00426,"epssPercentile":0.34846,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T12:17:24.433Z","addedAt":"2026-10-02T13:50:40.859Z","updatedAt":"2026-10-02T17:50:40.438Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-96294","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-96294","note":"authoritative record"}]},{"id":"eaca311a-a3e4-4ac0-85d5-97e243f00d8b","slug":"cve-2026-94646","externalId":"CVE-2026-94646","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-94646 — Uncaught exception, Improper validation of specified quantity in input, Improperly controlled modification of object prototype attributes ('prototy…","description":"Uncaught exception, Improper validation of specified quantity in input, Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift nodejs bindings.\n\n\n\nThis issue affects Apache Thrift: before 0.25.0.\n\n\n\nUsers are recommended to upgrade to version 0.25.0, which fixes the issue.","cveId":"CVE-2026-94646","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-248","CWE-1284","CWE-1321"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1","type":"advisory","title":"security@apache.org"},{"url":"https://lists.apache.org/thread/5hjh0gz8wf6bo7ydxjpqj92m42hwmfo8","type":"advisory","title":"security@apache.org"}],"epssScore":0.0046,"epssPercentile":0.3785,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T12:17:23.587Z","addedAt":"2026-10-02T13:50:40.829Z","updatedAt":"2026-10-02T15:50:40.958Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94646","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-94646","note":"authoritative record"}]},{"id":"bcd14972-2eab-4a8e-a6af-368982ec3150","slug":"cve-2026-90440","externalId":"CVE-2026-90440","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-90440 — Uncaught exception, improper handling of exceptional conditions, improper resource shutdown vulnerability in Apache Thrift D thrift.server.nonblock…","description":"Uncaught exception, improper handling of exceptional conditions, improper resource shutdown vulnerability in Apache Thrift D thrift.server.nonblocking.TNonblockingServer.\n\n\n\nThis issue affects Apache Thrift: before 0.25.0.\n\n\n\nUsers are recommended to upgrade to version 0.25.0, which fixes the issue.","cveId":"CVE-2026-90440","cvssScore":8.2,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-248","CWE-404","CWE-755"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1","type":"advisory","title":"security@apache.org"},{"url":"https://lists.apache.org/thread/s8fjltl6c1pkm7vg9v4qkr89b5b74jbg","type":"advisory","title":"security@apache.org"}],"epssScore":0.00426,"epssPercentile":0.34838,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T12:17:22.507Z","addedAt":"2026-10-02T13:50:40.804Z","updatedAt":"2026-10-02T15:50:40.929Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90440","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-90440","note":"authoritative record"}]},{"id":"31630fcc-81b0-4123-82f2-07c896f19b7d","slug":"cve-2026-86537","externalId":"CVE-2026-86537","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-86537 — Uncaught exception, Loop with unreachable exit condition ('infinite loop'), Integer underflow (wrap or wraparound) vulnerability in Apache Thrift D…","description":"Uncaught exception, Loop with unreachable exit condition ('infinite loop'), Integer underflow (wrap or wraparound) vulnerability in Apache Thrift D language bindings.\n\n\n\nThis issue affects Apache Thrift: before 0.25.0.\n\n\n\nUsers are recommended to upgrade to version 0.25.0, which fixes the issue.","cveId":"CVE-2026-86537","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-191","CWE-248","CWE-835"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1","type":"advisory","title":"security@apache.org"},{"url":"https://lists.apache.org/thread/k14jfr1xwc0vtmm2s7xro6lt7q4y6s7m","type":"advisory","title":"security@apache.org"}],"epssScore":0.00553,"epssPercentile":0.44426,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T12:17:22.233Z","addedAt":"2026-10-02T13:50:40.793Z","updatedAt":"2026-10-02T15:50:40.918Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86537","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-86537","note":"authoritative record"}]},{"id":"86483cac-798e-45c9-a541-9d95a698edd7","slug":"cve-2026-104434","externalId":"CVE-2026-104434","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-104434 — ZcashFoundation Zebra zebra-rpc before 8.0.0 and zebrad before 4.5.0 contain a reachable assertion in the z_listunifiedreceivers RPC handler, which…","description":"ZcashFoundation Zebra zebra-rpc before 8.0.0 and zebrad before 4.5.0 contain a reachable assertion in the z_listunifiedreceivers RPC handler, which calls expect() on Sapling receiver parsing that fails for Unified Addresses carrying invalid Jubjub points. Authenticated RPC clients can submit such an address to abort the zebrad process, repeatably keeping the node offline.","cveId":"CVE-2026-104434","cvssScore":7.1,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":"crates.io","product":"zebra-rpc","affectedVersions":["pkg:cargo/zebra-rpc < 8.0.0","pkg:cargo/zebrad < 4.5.0"],"cwes":["CWE-617","CWE-20","CWE-248","CWE-754"],"tags":["nvd","status:received","status:deferred","osv","osv:ghsa-c8w6-x74f-vmg3","ecosystem:crates.io"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-c8w6-x74f-vmg3","type":"other","title":"OSV web"},{"url":"https://www.vulncheck.com/advisories/zebra-before-8.0.0-denial-of-service-via-z-listunifiedreceivers-rpc","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://osv.dev/vulnerability/GHSA-c8w6-x74f-vmg3","type":"advisory","title":"OSV GHSA-c8w6-x74f-vmg3"},{"url":"https://github.com/ZcashFoundation/zebra","type":"vendor","title":"OSV package"},{"url":"https://github.com/ZcashFoundation/zebra/blob/d4cd662c716382f6397d2a730148025a1ca79fec/Cargo.toml#L305","type":"other","title":"OSV web"},{"url":"https://github.com/ZcashFoundation/zebra/blob/d4cd662c716382f6397d2a730148025a1ca79fec/zebra-rpc/src/methods.rs#L2867-L2914","type":"other","title":"OSV web"}],"epssScore":0.00307,"epssPercentile":0.2152,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T12:17:13.917Z","addedAt":"2026-10-02T13:50:40.510Z","updatedAt":"2026-10-03T07:54:20.110Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104434","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104434","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-C8W6-X74F-VMG3"}]},{"id":"1372117d-a8d8-4ef8-8a11-691f58a933cd","slug":"cve-2026-94642","externalId":"CVE-2026-94642","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-94642 — Uncaught exception vulnerability in Apache Thrift PHP bindings.","description":"Uncaught exception vulnerability in Apache Thrift PHP bindings.\n\n\n\nThis issue affects Apache Thrift: before 0.25.0.\n\n\n\nUsers are recommended to upgrade to version 0.25.0, which fixes the issue.","cveId":"CVE-2026-94642","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-248"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1","type":"advisory","title":"security@apache.org"},{"url":"https://lists.apache.org/thread/5tjwbbyympbj16lblocv9b12s32sg113","type":"advisory","title":"security@apache.org"}],"epssScore":0.00426,"epssPercentile":0.34843,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T11:17:38.377Z","addedAt":"2026-10-02T11:50:39.899Z","updatedAt":"2026-10-05T17:50:42.174Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94642","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-94642","note":"authoritative record"}]},{"id":"f3231a65-aa82-4b1d-beb9-20e536084cd7","slug":"cve-2026-85494","externalId":"CVE-2026-85494","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-85494 — Improper handling of length parameter inconsistency, Uncaught exception, Inefficient Algorithmic Complexity, Memory allocation with excessive size …","description":"Improper handling of length parameter inconsistency, Uncaught exception, Inefficient Algorithmic Complexity, Memory allocation with excessive size value, Initialization of a resource with an insecure default vulnerability in Apache Thrift Python, Ruby, Erlang, Lua, Dart, JavaME, Perl, PHP and D language bindings.\n\n\n\nThis issue affects Apache Thrift: before 0.25.0.\n\n\n\nUsers are recommended to upgrade to version 0.25.0, which fixes the issue.","cveId":"CVE-2026-85494","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-130","CWE-248","CWE-407","CWE-789","CWE-1188"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1","type":"advisory","title":"security@apache.org"},{"url":"https://lists.apache.org/thread/rm0m34gt6fh1flvt16wty559hfg191qr","type":"advisory","title":"security@apache.org"}],"epssScore":0.00467,"epssPercentile":0.38463,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T11:17:36.010Z","addedAt":"2026-10-02T11:50:39.855Z","updatedAt":"2026-10-08T00:39:29.153Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85494","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-85494","note":"authoritative record"}]},{"id":"e7d60aca-b2cd-4c63-95cd-8b2a6d39df31","slug":"cve-2026-85493","externalId":"CVE-2026-85493","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-85493 — Uncontrolled Recursion vulnerability in Apache Thrift Dart and Java ME bindings.","description":"Uncontrolled Recursion vulnerability in Apache Thrift Dart and Java ME bindings.\n\n\n\nThis issue affects Apache Thrift: before 0.25.0.\n\n\n\nUsers are recommended to upgrade to version 0.25.0, which fixes the issue.","cveId":"CVE-2026-85493","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-248","CWE-674"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1","type":"advisory","title":"security@apache.org"},{"url":"https://lists.apache.org/thread/oqr0h2k1cg9hho3oh8trmovmxc04fl5m","type":"advisory","title":"security@apache.org"}],"epssScore":0.00426,"epssPercentile":0.34846,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T11:17:35.877Z","addedAt":"2026-10-02T11:50:39.850Z","updatedAt":"2026-10-02T17:50:40.320Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85493","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-85493","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":150,"totalPages":8,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:57:01.205Z","durationMs":26,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-248"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}