{"success":true,"data":{"threats":[{"id":"0d0d63cf-fbe6-419b-8767-1aeb72bbb128","slug":"cve-2026-107390","externalId":"CVE-2026-107390","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107390 — music-metadata is a metadata parser for audio and video media files.","description":"music-metadata is a metadata parser for audio and video media files. Prior to 11.16.0, the MP4 parser accepts an attacker-controlled 64-bit extended atom size, converts it to a JavaScript Number, and uses the resulting payload length for atom-specific readToken calls before proving that the atom fits within its parent or the available input. A tiny MP4-family file can route an oversized length into payload parsing for atoms including mvhd, stsd, stsz, and date, causing a large allocation attempt or process failure before end-of-input validation. Applications that parse untrusted MP4-family media can therefore be denied service. This issue is fixed in version 11.16.0.","cveId":"CVE-2026-107390","cvssScore":6.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-789"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/Borewit/music-metadata/commit/0f19ad66d71889b1c5f3ba84d4824f079ac4c005","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/Borewit/music-metadata/pull/2746","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/Borewit/music-metadata/releases/tag/v11.16.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/Borewit/music-metadata/security/advisories/GHSA-qc8q-pw95-mq6c","type":"advisory","title":"security-advisories@github.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:33.357Z","addedAt":"2026-10-08T21:05:52.954Z","updatedAt":"2026-10-08T21:05:52.954Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107390","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107390","note":"authoritative record"}]},{"id":"c4f4e22a-cd59-4bb9-845d-b556f3c5c4ca","slug":"cve-2026-107389","externalId":"CVE-2026-107389","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107389 — music-metadata is a metadata parser for audio and video media files.","description":"music-metadata is a metadata parser for audio and video media files. Prior to 11.16.0, the Matroska and WebM EBML parser decodes an attacker-controlled VINT element length and uses it for string-token or Uint8Array allocation before confirming that the leaf fits within its parent or available input. Crafted WebM, MKV, or MKA inputs can cause disproportionate allocations, out-of-memory denial of service, or, for a demonstrated parseFile path on Node.js 26.7.0, an uncatchable V8 fatal abort. The exact failure mode depends on the tokenizer, parser API, and runtime, but the affected leaf-length validation flaw is shared and has availability impact only. This issue is fixed in version 11.16.0.","cveId":"CVE-2026-107389","cvssScore":6.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":"npm","product":"music-metadata","affectedVersions":["pkg:npm/music-metadata < 11.16.0"],"cwes":["CWE-789"],"tags":["nvd","status:awaiting-analysis","osv","osv:ghsa-5gfj-9q3v-qfp3","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/Borewit/music-metadata/commit/163f013364ac9fc8dd0c3987433cd065a615af58","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/commit/2d14dc1f7391a94235948a0b823155538f69b3df","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/pull/2735","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/releases/tag/v11.16.0","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/security/advisories/GHSA-5gfj-9q3v-qfp3","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-5gfj-9q3v-qfp3","type":"advisory","title":"OSV GHSA-5gfj-9q3v-qfp3"},{"url":"https://github.com/Borewit/music-metadata","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:33.190Z","addedAt":"2026-10-08T21:05:52.914Z","updatedAt":"2026-10-08T21:08:30.863Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107389","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107389","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-5GFJ-9Q3V-QFP3"}]},{"id":"43a625d7-28ac-491d-8004-2e7bc4f38e3f","slug":"cve-2026-107388","externalId":"CVE-2026-107388","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107388 — music-metadata is a metadata parser for audio and video media files.","description":"music-metadata is a metadata parser for audio and video media files. Prior to 11.16.0, the ID3v2 parser trusts the syncsafe tag-size field and allocates the complete tag body before checking whether the input contains the declared bytes. A truncated file containing only an ID3v2 header can request an allocation approaching 268 MiB; the allocation succeeds, the subsequent read reaches end of stream, the EndOfStreamError is caught internally, and the caller receives a normal metadata object. This issue is fixed in version 11.16.0.","cveId":"CVE-2026-107388","cvssScore":6.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":"npm","product":"music-metadata","affectedVersions":["pkg:npm/music-metadata < 11.16.0"],"cwes":["CWE-789"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-jjpr-9cvf-cq55","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/Borewit/music-metadata/commit/b033db675b913a9dba1d29135ec3c10eae7095a7","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/pull/2743","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/releases/tag/v11.16.0","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/security/advisories/GHSA-jjpr-9cvf-cq55","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-jjpr-9cvf-cq55","type":"advisory","title":"OSV GHSA-jjpr-9cvf-cq55"},{"url":"https://github.com/Borewit/music-metadata","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T19:17:01.683Z","addedAt":"2026-10-08T19:33:17.007Z","updatedAt":"2026-10-08T21:08:30.703Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107388","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107388","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-JJPR-9CVF-CQ55"}]},{"id":"9c90aa17-2b67-433b-85d6-bd6a13643ed7","slug":"cve-2026-107387","externalId":"CVE-2026-107387","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107387 — music-metadata is a metadata parser for audio and video media files.","description":"music-metadata is a metadata parser for audio and video media files. Prior to 11.16.0, the APEv2 parser reads an attacker-controlled tag-item size and allocates a Uint8Array for a binary item before proving that the declared item fits in the remaining tag or file data. A small crafted APE file can therefore trigger a disproportionate allocation, including through cover-art items, and repeated or concurrent parsing can exhaust process memory. The demonstrated impact is availability loss only. This issue is fixed in version 11.16.0.","cveId":"CVE-2026-107387","cvssScore":6.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":"npm","product":"music-metadata","affectedVersions":["pkg:npm/music-metadata < 11.16.0"],"cwes":["CWE-789"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-53v6-4h7p-p4gj","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/Borewit/music-metadata/commit/b3bf52cb6021b046f33ba47583e19ab8f10dd235","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/pull/2744","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/releases/tag/v11.16.0","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/security/advisories/GHSA-53v6-4h7p-p4gj","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-53v6-4h7p-p4gj","type":"advisory","title":"OSV GHSA-53v6-4h7p-p4gj"},{"url":"https://github.com/Borewit/music-metadata","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T19:17:01.517Z","addedAt":"2026-10-08T19:33:16.996Z","updatedAt":"2026-10-08T21:08:30.899Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107387","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107387","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-53V6-4H7P-P4GJ"}]},{"id":"23b0180f-fd14-4354-8729-d7be931396d9","slug":"cve-2026-107223","externalId":"CVE-2026-107223","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107223 — Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets.","description":"Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.1.0 to 2.11.0, flatCols expands file-loaded column ranges without validating Min and Max against the worksheet column limit. SetColWidth reaches flatCols, which expands xlsxCol.Min through xlsxCol.Max without enforcing MaxColumns. When a crafted worksheet supplies an oversized col max attribute and the application invokes a column mutator, flatCols performs a deep copy and append for every attacker-selected column number, allowing an attacker to consume excessive CPU and memory or trigger OOM. No fixed version is available as of this review.","cveId":"CVE-2026-107223","cvssScore":7.1,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":"Go","product":"github.com/xuri/excelize/v2","affectedVersions":["pkg:golang/github.com/xuri/excelize/v2 >= 2.1.0, < 2.11.1-0.20260807015645-a54c578af309"],"cwes":["CWE-789"],"tags":["nvd","status:received","osv","osv:ghsa-fq3v-74gv-27gm","ecosystem:go","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/qax-os/excelize/commit/a54c578af309fa81f448143ed2b7a91192cc58a7","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/qax-os/excelize/pull/2370","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/qax-os/excelize/security/advisories/GHSA-fq3v-74gv-27gm","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-fq3v-74gv-27gm","type":"advisory","title":"OSV GHSA-fq3v-74gv-27gm"},{"url":"https://github.com/qax-os/excelize","type":"vendor","title":"OSV package"}],"epssScore":0.00317,"epssPercentile":0.22589,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T19:17:34.970Z","addedAt":"2026-10-07T20:39:40.431Z","updatedAt":"2026-10-08T21:05:43.678Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107223","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107223","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-FQ3V-74GV-27GM"}]},{"id":"16105d77-cbc0-4ece-87fc-96b82dc14bbc","slug":"cve-2026-107215","externalId":"CVE-2026-107215","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107215 — Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets.","description":"Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, extractPart allocates a byte slice directly from an attacker-controlled CFB directory-entry size before validating the sector chain or size domain. extractPart trusts the CFB directory entry streamSize for EncryptionInfo and EncryptedPackage allocations before validating the stream. When a crafted OLE compound file declares a negative or extremely large EncryptionInfo or EncryptedPackage stream size, the declared size reaches make with a negative length or forces a multi-gigabyte allocation, allowing an attacker to panic or exhaust process memory. No fixed version is available as of this review.","cveId":"CVE-2026-107215","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":"Go","product":"github.com/xuri/excelize/v2","affectedVersions":["pkg:golang/github.com/xuri/excelize/v2 >= 2.3.1, < 2.11.1-0.20260912113515-5f636f9dcde5"],"cwes":["CWE-789"],"tags":["nvd","status:received","osv","osv:ghsa-x2q3-8cjh-766f","ecosystem:go","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/qax-os/excelize/commit/5f636f9dcde55911f14290060b017f0cc88cd694","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/qax-os/excelize/pull/2396","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/qax-os/excelize/security/advisories/GHSA-x2q3-8cjh-766f","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-x2q3-8cjh-766f","type":"advisory","title":"OSV GHSA-x2q3-8cjh-766f"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107215","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/qax-os/excelize","type":"vendor","title":"OSV package"}],"epssScore":0.00223,"epssPercentile":0.11892,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T18:17:19.213Z","addedAt":"2026-10-07T18:39:31.692Z","updatedAt":"2026-10-08T21:05:43.422Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107215","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107215","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-X2Q3-8CJH-766F"}]},{"id":"0eaf0a3d-382a-4e68-9acb-f99127330c36","slug":"cve-2026-106569","externalId":"CVE-2026-106569","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106569 — ImageMagick is free and open-source software used for editing and manipulating digital images.","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32, missing validation and resource checks in the ASE decoder allow a crafted ASE image to cause a crash or a long-running operation. This issue is fixed in version 7.1.2-32.","cveId":"CVE-2026-106569","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-770","CWE-789"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/ImageMagick/ImageMagick/commit/0691546106f4c7e8857da9f21a0e4a8f41915388","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick/commit/5ecd5b047cee7ccfe4e14a733a0755c7b2a90c7d","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-gwj6-pm7x-3r63","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00384,"epssPercentile":0.30341,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T16:17:42.503Z","addedAt":"2026-10-07T16:39:32.577Z","updatedAt":"2026-10-08T21:05:41.998Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106569","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106569","note":"authoritative record"}]},{"id":"cf527769-6ce2-48af-a134-5d3954fc1e78","slug":"cve-2026-106453","externalId":"CVE-2026-106453","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106453 — yawkat LZ4 Java provides LZ4 compression for Java.","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, LZ4DecompressorWithLength uses getDecompressedLength to trust the four-byte decompressed-length header before validating the compressed input, allowing a five-byte attacker-supplied input whose header declares a large output size to request up to approximately 2 GiB and exhaust the JVM heap. Convenience overloads backed by LZ4FastDecompressor or LZ4SafeDecompressor allocate the untrusted size, while overloads that write to a caller-provided destination buffer are not affected because the caller controls the destination size. This issue is fixed in version 1.11.2.","cveId":"CVE-2026-106453","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","severity":"medium","vendor":"Maven","product":"at.yawk.lz4:lz4-java","affectedVersions":["pkg:maven/at.yawk.lz4/lz4-java < 1.11.2","pkg:maven/org.lz4/lz4-java <= 1.8.1"],"cwes":["CWE-789"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-6cx8-rjf8-pr8g","ecosystem:maven"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/yawkat/lz4-java/commit/6492ce5aca6bd03ff9e08ee18a2beb94c431371a","type":"other","title":"OSV web"},{"url":"https://github.com/yawkat/lz4-java/releases/tag/v1.11.2","type":"other","title":"OSV web"},{"url":"https://github.com/yawkat/lz4-java/security/advisories/GHSA-6cx8-rjf8-pr8g","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-6cx8-rjf8-pr8g","type":"advisory","title":"OSV GHSA-6cx8-rjf8-pr8g"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106453","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/yawkat/lz4-java","type":"vendor","title":"OSV package"}],"epssScore":0.00371,"epssPercentile":0.28981,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T20:17:27.457Z","addedAt":"2026-10-06T20:39:33.124Z","updatedAt":"2026-10-07T18:42:44.842Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106453","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106453","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-6CX8-RJF8-PR8G"}]},{"id":"9907ceae-d4c4-4433-97d0-a73865fe8e93","slug":"cve-2026-106452","externalId":"CVE-2026-106452","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106452 — yawkat LZ4 Java provides LZ4 compression for Java.","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, net.jpountz.lz4.LZ4BlockInputStream refill() validates that the compressedLen field in a legacy LZ4Block header is nonnegative but allocates a compressed-input buffer of that attacker-controlled size before reading payload data, allowing a header-only stream to request a near-2 GiB allocation and exhaust the JVM heap. Canonical writers emit raw blocks when compression is not smaller than the original block, but vulnerable readers accept non-canonical oversized compressed blocks. This issue is fixed in version 1.11.2.","cveId":"CVE-2026-106452","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","severity":"medium","vendor":"Maven","product":"at.yawk.lz4:lz4-java","affectedVersions":["pkg:maven/at.yawk.lz4/lz4-java < 1.11.2","pkg:maven/org.lz4/lz4-java <= 1.8.1"],"cwes":["CWE-789"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-4v53-57pg-c464","ecosystem:maven"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/yawkat/lz4-java/commit/bb83dd16163cdb71231af06b0a5651881148a634","type":"other","title":"OSV web"},{"url":"https://github.com/yawkat/lz4-java/releases/tag/v1.11.2","type":"other","title":"OSV web"},{"url":"https://github.com/yawkat/lz4-java/security/advisories/GHSA-4v53-57pg-c464","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-4v53-57pg-c464","type":"advisory","title":"OSV GHSA-4v53-57pg-c464"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106452","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/yawkat/lz4-java","type":"vendor","title":"OSV package"}],"epssScore":0.00371,"epssPercentile":0.28981,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T20:17:27.317Z","addedAt":"2026-10-06T20:39:33.116Z","updatedAt":"2026-10-07T18:42:44.953Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106452","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106452","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-4V53-57PG-C464"}]},{"id":"0f0d62e7-9c22-4114-9160-89dec1b778c2","slug":"cve-2026-103005","externalId":"CVE-2026-103005","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-103005 — Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130).","description":"Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with connector management privileges could cause the cluster to allocate an uncontrolled amount of memory when connector resources with an excessively large `description` field are created and subsequently accessed, exhausting available heap memory and crashing the affected node.","cveId":"CVE-2026-103005","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-789"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://discuss.elastic.co/t/elasticsearch-8-19-23-9-4-8-9-5-5-security-update-esa-2026-195/390869","type":"advisory","title":"security@elastic.co"}],"epssScore":0.00302,"epssPercentile":0.21055,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T20:17:13.597Z","addedAt":"2026-10-06T20:39:32.867Z","updatedAt":"2026-10-07T14:39:34.025Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103005","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-103005","note":"authoritative record"}]},{"id":"e0df9b5d-91ab-4393-8c11-6015e429340f","slug":"cve-2026-106114","externalId":"CVE-2026-106114","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106114 — ImageSharp is a 2D graphics library.","description":"ImageSharp is a 2D graphics library. From 1.0.0-beta0001 until 4.1.2, ICC CLUT parsing calculates allocation sizes from attacker-declared channel and grid dimensions before confirming that the profile contains the declared values. IccDataReader.ReadClutF32 can request a large float array, and earlier public IccProfile.Entries parsing paths can allocate a large jagged representation, from a short truncated profile. In version 4, automatic image conversion reaches the parser when DecoderOptions.ColorProfileHandling is Convert; the default Preserve mode avoids that conversion path. The demonstrated impact is memory pressure and input-validation failure, not unhandled process termination. This issue is fixed in version 4.1.2.","cveId":"CVE-2026-106114","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-789"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/SixLabors/ImageSharp/commit/8de892a7623aa8a09ba2333b624c8d2eb98325df","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/SixLabors/ImageSharp/pull/3187","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-gwg2-r3hj-4w44","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epssScore":0.00366,"epssPercentile":0.28364,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T18:16:53.100Z","addedAt":"2026-10-06T18:39:27.594Z","updatedAt":"2026-10-06T20:39:30.257Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106114","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106114","note":"authoritative record"}]},{"id":"4429cfb0-22c4-422e-a883-c3c6ad184883","slug":"cve-2026-77050","externalId":"CVE-2026-77050","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-77050 — An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18.","description":"An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18.\n`django.utils.translation.get_supported_language_variant()` is subject to\r\na potential denial-of-service attack when processing many distinct, very long\r\nlanguage codes, which are retained as keys in an in-memory cache and\r\nconsume process memory.\nEarlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected.\nDjango would like to thank Gleb Lizunov for reporting this issue.","cveId":"CVE-2026-77050","cvssScore":6.9,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-789"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://docs.djangoproject.com/en/dev/releases/security/","type":"advisory","title":"6a34fbeb-21d4-45e7-8e0a-62b95bc12c92"},{"url":"https://github.com/django/django/commit/02a69e3791e3df23d45ea4ea7e7fc489f0eef2be","type":"advisory","title":"6a34fbeb-21d4-45e7-8e0a-62b95bc12c92"},{"url":"https://github.com/django/django/commit/3d32ee80ae52745d686bf94d3555000ddf073267","type":"advisory","title":"6a34fbeb-21d4-45e7-8e0a-62b95bc12c92"},{"url":"https://github.com/django/django/commit/7e878b0f8bd42260903e6a0d38996a93b0474a0b","type":"advisory","title":"6a34fbeb-21d4-45e7-8e0a-62b95bc12c92"},{"url":"https://github.com/django/django/commit/c88b304cc2d90fc37d3bd1f5f3829706fa6c13bc","type":"advisory","title":"6a34fbeb-21d4-45e7-8e0a-62b95bc12c92"},{"url":"https://groups.google.com/g/django-announce","type":"advisory","title":"6a34fbeb-21d4-45e7-8e0a-62b95bc12c92"},{"url":"https://www.djangoproject.com/weblog/2026/oct/06/security-releases/","type":"advisory","title":"6a34fbeb-21d4-45e7-8e0a-62b95bc12c92"}],"epssScore":0.00381,"epssPercentile":0.30011,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T14:17:46.017Z","addedAt":"2026-10-06T15:51:00.341Z","updatedAt":"2026-10-06T15:51:00.341Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-77050","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-77050","note":"authoritative record"}]},{"id":"51ea1034-8e1f-45ab-bc96-df54ccc47b83","slug":"cve-2026-105749","externalId":"CVE-2026-105749","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105749 — Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem.","description":"Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.0.0 until 2.131.0, the HTML, JATS, OpenDocument spreadsheet, and BoxNote backends, including docling/backend/html_backend.py, docling/backend/jats_backend.py, and docling/backend/boxnote_backend.py, accept the rowspan and colspan attribute values without an upper bound and execute loops or allocate a table grid proportional to the declared span. A very small document can therefore cause sustained CPU use or multi-gigabyte memory allocation, and the document_timeout setting does not interrupt the single backend conversion call. Export through the TableData.grid property can further materialize the oversized grid. This issue is fixed in 2.131.0.","cveId":"CVE-2026-105749","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","severity":"medium","vendor":"docling","product":"docling","affectedVersions":[">= 2.0.0, < 2.131.0","pkg:pypi/docling >= 2.0.0, < 2.131.0","pkg:pypi/docling-slim >= 2.92.0, < 2.131.0"],"cwes":["CWE-400","CWE-789"],"tags":["nvd","status:received","status:undergoing-analysis","status:analyzed","osv","osv:ghsa-cgc7-9qp3-86m3","ecosystem:pypi","status:modified","osv:pysec-2026-4195"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/docling-project/docling/commit/c5b4429cc6500a344c13edeb22e67610c2159b09","https://github.com/docling-project/docling/pull/4414","https://github.com/docling-project/docling/security/advisories/GHSA-cgc7-9qp3-86m3"],"references":[{"url":"https://github.com/docling-project/docling/commit/c5b4429cc6500a344c13edeb22e67610c2159b09","type":"patch","title":"OSV fix"},{"url":"https://github.com/docling-project/docling/pull/4414","type":"patch","title":"OSV fix"},{"url":"https://github.com/docling-project/docling/releases/tag/v2.131.0","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/docling-project/docling/security/advisories/GHSA-cgc7-9qp3-86m3","type":"patch","title":"OSV fix"},{"url":"https://osv.dev/vulnerability/GHSA-cgc7-9qp3-86m3","type":"advisory","title":"OSV GHSA-cgc7-9qp3-86m3"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105749","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/docling-project/docling","type":"vendor","title":"OSV package"},{"url":"https://osv.dev/vulnerability/PYSEC-2026-4195","type":"advisory","title":"OSV PYSEC-2026-4195"}],"epssScore":0.00266,"epssPercentile":0.16968,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T22:16:57.943Z","addedAt":"2026-10-05T23:50:40.412Z","updatedAt":"2026-10-08T12:42:40.313Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105749","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105749","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-CGC7-9QP3-86M3"}]},{"id":"5e77233b-8a52-4835-b8d8-bf4e1ab27992","slug":"cve-2026-78861","externalId":"CVE-2026-78861","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-78861 — An issue in Mercusys AC12 V2 allows a local attacker to execute arbitrary code via a hardcoded 512-bit RSA Private Key","description":"An issue in Mercusys AC12 V2 allows a local attacker to execute arbitrary code via a hardcoded 512-bit RSA Private Key","cveId":"CVE-2026-78861","cvssScore":7.7,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-789"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"http://ac12.com/","type":"advisory","title":"cve@mitre.org"},{"url":"http://mercusys.com/","type":"advisory","title":"cve@mitre.org"},{"url":"https://threadpoolx.gitbook.io/docs/cve/mercusys-ac12-v2-security-advisory/hardcoded-private-key","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epssScore":0.00136,"epssPercentile":0.0261,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T20:17:27.427Z","addedAt":"2026-10-05T21:50:41.104Z","updatedAt":"2026-10-06T17:50:42.175Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-78861","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-78861","note":"authoritative record"}]},{"id":"68d374cc-b56b-4ed7-8dec-7bee7260f500","slug":"cve-2026-93323","externalId":"CVE-2026-93323","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-93323 — The Dockerfile frontend loaded the Dockerfile and .dockerignore files of a build context into memory without a size limit.","description":"The Dockerfile frontend loaded the Dockerfile and .dockerignore files of a build context into memory without a size limit. A build context containing an oversized file could make buildkitd allocate memory proportional to that file, potentially exhausting memory and terminating the daemon, which interrupts other builds on the same instance. Fixed by rejecting such files above 16 MiB.","cveId":"CVE-2026-93323","cvssScore":6.8,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-789"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/moby/buildkit/releases/tag/v0.33.1","type":"advisory","title":"security@docker.com"},{"url":"https://github.com/moby/buildkit/security/advisories/GHSA-mgqf-486f-49vp","type":"advisory","title":"security@docker.com"}],"epssScore":0.00107,"epssPercentile":0.01052,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T18:17:39.630Z","addedAt":"2026-10-05T19:50:42.684Z","updatedAt":"2026-10-06T15:50:57.966Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93323","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-93323","note":"authoritative record"}]},{"id":"558423d1-a566-45f4-a62c-406cf3d4a2e4","slug":"cve-2026-83745","externalId":"CVE-2026-83745","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-83745 — Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift \nnodejs and D lang …","description":"Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift \nnodejs and D lang bindings.\n\nBoth bindings' WebSocket server transports read the payload length out of the frame header and allocate that many bytes immediately, without checking that the bytes have arrived. A single ~14-byte frame therefore commits as much memory as it cares to declare -- measured at 513 MiB against the Node.js server and 2 GiB against the D transport -- and in the Node.js case the connection is left open afterwards, so the frame can simply be sent again.\n\n\n\n\nThis issue affects Apache Thrift before 0.25.0.\n\n\n\nUsers are recommended to upgrade to version 0.25.0, which fixes the issue.","cveId":"CVE-2026-83745","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-130","CWE-789"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1","type":"advisory","title":"security@apache.org"},{"url":"https://lists.apache.org/thread/64y7f0b89mnq4xoqcn4h26to8kskolgc","type":"advisory","title":"security@apache.org"}],"epssScore":0.00426,"epssPercentile":0.34844,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T13:17:58.927Z","addedAt":"2026-10-02T13:50:40.968Z","updatedAt":"2026-10-02T19:50:41.425Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-83745","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-83745","note":"authoritative record"}]},{"id":"335ef993-c9df-4e0a-af6b-61cbc1a2ca88","slug":"cve-2026-82458","externalId":"CVE-2026-82458","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-82458 — Memory allocation with excessive size value, Allocation of resources without limits or throttling vulnerability in Apache Thrift Go, netstd, OCaml,…","description":"Memory allocation with excessive size value, Allocation of resources without limits or throttling vulnerability in Apache Thrift Go, netstd, OCaml, Erlang, JavaME, Rust, C++, Java, Kotlin and D language bindings.\n\n\n\n\nThis issue affects Apache Thrift: before 0.25.0.\n\n\n\nUsers are recommended to upgrade to version 0.25.0, which fixes the issue.","cveId":"CVE-2026-82458","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-770","CWE-789"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1","type":"advisory","title":"security@apache.org"},{"url":"https://lists.apache.org/thread/7xqf651pvjykw0xr9vw0ooz0bwx7wzy7","type":"advisory","title":"security@apache.org"}],"epssScore":0.00426,"epssPercentile":0.34847,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T12:17:21.173Z","addedAt":"2026-10-02T13:50:40.754Z","updatedAt":"2026-10-02T19:50:41.352Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-82458","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-82458","note":"authoritative record"}]},{"id":"4c356280-9498-4b13-a591-25f48d858a22","slug":"cve-2026-94633","externalId":"CVE-2026-94633","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-94633 — Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift Dart bindings.","description":"Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift Dart bindings.\n\n\n\nThis issue affects Apache Thrift: before 0.25.0.\n\n\n\nUsers are recommended to upgrade to version 0.25.0, which fixes the issue.","cveId":"CVE-2026-94633","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-130","CWE-789"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1","type":"advisory","title":"security@apache.org"},{"url":"https://lists.apache.org/thread/cxkbblyht7988p2o6yvnmd6536qmt88k","type":"advisory","title":"security@apache.org"}],"epssScore":0.00426,"epssPercentile":0.34843,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T11:17:38.247Z","addedAt":"2026-10-02T11:50:39.894Z","updatedAt":"2026-10-02T15:50:40.666Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94633","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-94633","note":"authoritative record"}]},{"id":"f3231a65-aa82-4b1d-beb9-20e536084cd7","slug":"cve-2026-85494","externalId":"CVE-2026-85494","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-85494 — Improper handling of length parameter inconsistency, Uncaught exception, Inefficient Algorithmic Complexity, Memory allocation with excessive size …","description":"Improper handling of length parameter inconsistency, Uncaught exception, Inefficient Algorithmic Complexity, Memory allocation with excessive size value, Initialization of a resource with an insecure default vulnerability in Apache Thrift Python, Ruby, Erlang, Lua, Dart, JavaME, Perl, PHP and D language bindings.\n\n\n\nThis issue affects Apache Thrift: before 0.25.0.\n\n\n\nUsers are recommended to upgrade to version 0.25.0, which fixes the issue.","cveId":"CVE-2026-85494","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-130","CWE-248","CWE-407","CWE-789","CWE-1188"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1","type":"advisory","title":"security@apache.org"},{"url":"https://lists.apache.org/thread/rm0m34gt6fh1flvt16wty559hfg191qr","type":"advisory","title":"security@apache.org"}],"epssScore":0.00467,"epssPercentile":0.38463,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T11:17:36.010Z","addedAt":"2026-10-02T11:50:39.855Z","updatedAt":"2026-10-08T00:39:29.153Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85494","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-85494","note":"authoritative record"}]},{"id":"192b569c-7ee5-42ec-b621-42e5691f8171","slug":"cve-2026-102731","externalId":"CVE-2026-102731","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-102731 — Memory allocation with excessive size value vulnerability in Apache Directory LDAP API.","description":"Memory allocation with excessive size value vulnerability in Apache Directory LDAP API.\n\n\n\nA malicious peer (or a MITM) can send a small BER-encoded response causing a large memory allocation before any data is received. This can lead to an OutOfMemoryError and denial of service.\n\n\n\nThe client JVM OOMs (OutOfMemoryError bypasses the DecoderException handlers) or pins the large allocation per connection while the attacker stalls.\n\n\n\nA handful of connections exhausts any heap. The same bytes from an unauthenticated pre-bind client hit any embedding server that did not set MAX_PDU_SIZE_ATTR.\n\n\n\nThis issue affects Apache Directory LDAP API: from 1.2.0 before 1.2.9.\n\n\n\nUsers are recommended to upgrade to version 1.2.9, which fixes the issue.","cveId":"CVE-2026-102731","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-789"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread.html/b8kg8881pc0v8lp59w0fcfrs69wjbqvd","type":"advisory","title":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/10/02/3","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"}],"epssScore":0.0043,"epssPercentile":0.35201,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T10:17:04.530Z","addedAt":"2026-10-02T11:50:39.666Z","updatedAt":"2026-10-05T19:50:42.315Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102731","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-102731","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":143,"totalPages":8,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:56:01.368Z","durationMs":17,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-789"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}