{"success":true,"data":{"threats":[{"id":"058f0d42-6c83-46b2-ac64-ab25a6feb0d3","slug":"cve-2026-107391","externalId":"CVE-2026-107391","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107391 — music-metadata is a metadata parser for audio and video media files.","description":"music-metadata is a metadata parser for audio and video media files. In the public development revision introduced after 11.14.0, a development-branch regression in the MP4 stsd sample-description parser allows an attacker-controlled sample-entry size of zero to prevent the StsdAtom.get cursor from advancing while an attacker-controlled entry_count keeps the synchronous loop running. A crafted MP4-family input can block the Node.js event loop and grow the sample-description table until the process is terminated or exhausts memory. The vulnerable change was present on the public master branch but was not included in music-metadata 11.14.0 or any earlier npm release, and version 11.16.0 contains the fix. This issue is fixed in version 11.16.0.","cveId":"CVE-2026-107391","cvssScore":6.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":"npm","product":"music-metadata","affectedVersions":["pkg:npm/music-metadata < 11.16.0"],"cwes":["CWE-400","CWE-835"],"tags":["nvd","status:awaiting-analysis","osv","osv:ghsa-f94x-6692-553q","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/Borewit/music-metadata/commit/90a7d52c69e921a0b019592d887acd97b1c8b8a5","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/pull/2734","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/releases/tag/v11.16.0","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/security/advisories/GHSA-f94x-6692-553q","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-f94x-6692-553q","type":"advisory","title":"OSV GHSA-f94x-6692-553q"},{"url":"https://github.com/Borewit/music-metadata","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:33.530Z","addedAt":"2026-10-08T21:05:52.968Z","updatedAt":"2026-10-08T21:08:30.734Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107391","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107391","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-F94X-6692-553Q"}]},{"id":"8c1818ee-6d1d-4803-97f5-ea2654c7eedd","slug":"cve-2026-107696","externalId":"CVE-2026-107696","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107696 — FFmpeg through 9.0.2 contains an infinite loop vulnerability in ff_rtsp_connect() in libavformat/rtsp.c that follows RTSP 3xx redirects without any…","description":"FFmpeg through 9.0.2 contains an infinite loop vulnerability in ff_rtsp_connect() in libavformat/rtsp.c that follows RTSP 3xx redirects without any redirect limit. Attackers controlling an RTSP server can answer every request with a 302 redirect to itself or another server, causing endless reconnects that saturate a CPU core.","cveId":"CVE-2026-107696","cvssScore":7.1,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-835"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24902","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://gist.github.com/OxBat/648a0bd60c898f2ffb418e131ce26013","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/FFmpeg/FFmpeg","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/FFmpeg/FFmpeg/blob/n9.0.2/libavformat/rtsp.c#L2225","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/ffmpeg-through-9.0.2-infinite-loop-via-rtsp-redirect-handling-in-rtsp-c","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T18:17:26.133Z","addedAt":"2026-10-08T18:39:31.932Z","updatedAt":"2026-10-08T23:06:38.898Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107696","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107696","note":"authoritative record"}]},{"id":"93ef25fe-9ebe-4fd7-b5ea-42c69a8ccf30","slug":"cve-2026-107695","externalId":"CVE-2026-107695","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107695 — FFmpeg before 8.1.3 contains an infinite loop vulnerability in the HLS demuxer that allows remote attackers to cause denial of service because pars…","description":"FFmpeg before 8.1.3 contains an infinite loop vulnerability in the HLS demuxer that allows remote attackers to cause denial of service because parse_playlist() accepts Master Playlist tags inside Media Playlists. Attackers can trick victims into opening a crafted self-referencing playlist that endlessly adds variants in hls_read_header(), causing unbounded CPU and I/O consumption.","cveId":"CVE-2026-107695","cvssScore":7.1,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-835"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23618","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://gist.github.com/OxBat/59574a2940092cda1b6e76bbf96f53d0","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/FFmpeg/FFmpeg","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/FFmpeg/FFmpeg/blob/n8.1.2/libavformat/hls.c#L866","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/FFmpeg/FFmpeg/commit/0e6eef35517a","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/FFmpeg/FFmpeg/commit/a4ddaba8bb78","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/FFmpeg/FFmpeg/commit/c364ab176f722bdabc886845e770c9eacbc1e3e5","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/ffmpeg-before-8.1.3-hls-demuxer-infinite-loop-via-self-referencing-playlist","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T18:17:25.967Z","addedAt":"2026-10-08T18:39:31.925Z","updatedAt":"2026-10-08T23:06:38.881Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107695","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107695","note":"authoritative record"}]},{"id":"5c1be768-d205-44a7-8597-002828f7ec39","slug":"cve-2026-107677","externalId":"CVE-2026-107677","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107677 — FFmpeg through 9.0.2 contains a denial of service vulnerability in the DASH demuxer that allows attackers to trigger an infinite loop by supplying …","description":"FFmpeg through 9.0.2 contains a denial of service vulnerability in the DASH demuxer that allows attackers to trigger an infinite loop by supplying an empty SegmentTemplate media URL. Attackers can craft an .mpd manifest declaring SegmentTemplate media=\"\" so get_current_fragment() calls av_strireplace() with an empty search string, consuming CPU indefinitely.","cveId":"CVE-2026-107677","cvssScore":5.7,"cvssVector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-835"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/ed27bfcbbbc0872c0195eaf4dd2c0c93b9f1778e","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24592","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://ffmpeg.org/","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/FFmpeg/FFmpeg/blob/n9.0.2/libavformat/dashdec.c#L1726","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/FFmpeg/FFmpeg/blob/n9.0.2/libavutil/avstring.c#L230-L238","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/ffmpeg-through-9.0.2-dash-demuxer-infinite-loop-via-empty-segmenttemplate-media","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T16:17:05.430Z","addedAt":"2026-10-08T16:39:36.056Z","updatedAt":"2026-10-08T23:06:38.450Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107677","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107677","note":"authoritative record"}]},{"id":"d0159003-3429-46d5-8edf-6bc80b3b4116","slug":"cve-2026-107577","externalId":"CVE-2026-107577","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107577 — Inefficient algorithmic complexity and a non-terminating loop in the MIME processing of received messages in Progressive Robot hMailServer 6.0.0 th…","description":"Inefficient algorithmic complexity and a non-terminating loop in the MIME processing of received messages in Progressive Robot hMailServer 6.0.0 through 6.3.5 allow a remote unauthenticated attacker to make the mail services unavailable by sending a message. Removing a MIME header parameter whose value is empty and directly followed by a semicolon (for example a Content-Disposition with 'filename=a.bat; filename=;') entered a loop that never terminates, holding a worker thread at full load until the server is restarted; this is reached when the attachment blocker renames a blocked attachment or a filename is set over the REST API. Separately, decoding a header field that holds many RFC 2047 encoded words of an encoding other than base64 or quoted-printable, removing a parameter with many RFC 2231 continuations, and deleting many header fields of one name each took time growing with the square of the message, on the small thread pools that serve IMAP, SMTP and POP3 connections, delivery and the REST API.","cveId":"CVE-2026-107577","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-835"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://gitlab.com/hmailserver/hmailserver/-/releases/v6.3.6","type":"advisory","title":"cve@gitlab.com"},{"url":"https://gitlab.com/hmailserver/hmailserver/-/work_items/72","type":"advisory","title":"cve@gitlab.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T12:17:15.630Z","addedAt":"2026-10-08T12:39:41.358Z","updatedAt":"2026-10-08T23:06:37.682Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107577","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107577","note":"authoritative record"}]},{"id":"583b48a7-dce1-4728-a9ff-23b41f9c2053","slug":"cve-2026-106164","externalId":"CVE-2026-106164","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106164 — In Progress® Telerik® Document Processing SpreadProcessing library, versions prior to 2026.3.1006, an infinite loop vulnerability exists when impor…","description":"In Progress® Telerik® Document Processing SpreadProcessing library, versions prior to 2026.3.1006, an infinite loop vulnerability exists when importing an XLS file with a specifically-targted corruption, the import timeout is ignored resulting in an unresponsive CPU thread and denial of service.","cveId":"CVE-2026-106164","cvssScore":7.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-835"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.telerik.com/document-processing-libraries/documentation/knowledge-base/kb-security-import-infinite-loop-cve-2026-106164","type":"advisory","title":"security@progress.com"}],"epssScore":0.00186,"epssPercentile":0.07561,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T19:17:31.987Z","addedAt":"2026-10-07T20:39:40.378Z","updatedAt":"2026-10-08T21:05:43.460Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106164","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106164","note":"authoritative record"}]},{"id":"187c19c6-b07e-4930-bebb-96a2b16290df","slug":"cve-2026-106568","externalId":"CVE-2026-106568","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106568 — ImageMagick is free and open-source software used for editing and manipulating digital images.","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted XMP profile embedded in an image can cause the profile parser to enter an infinite loop, preventing image processing from completing. This issue is fixed in versions 7.1.2-32 and 6.9.13-57.","cveId":"CVE-2026-106568","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-835"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/ImageMagick/ImageMagick/commit/e4f7ad983df6c831832eba3689f96b75f8b67051","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9p7q-63hw-mcr4","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick6/commit/27e36ca5cb446664bfc284d28d91fced8887b025","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-57","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00384,"epssPercentile":0.30341,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T16:17:41.143Z","addedAt":"2026-10-07T16:39:32.569Z","updatedAt":"2026-10-08T21:05:41.971Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106568","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106568","note":"authoritative record"}]},{"id":"947ee80c-b125-43f2-943c-b897099f47c6","slug":"cve-2026-106567","externalId":"CVE-2026-106567","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106567 — ImageMagick is free and open-source software used for editing and manipulating digital images.","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted PSD file can trigger an integer-conversion error in the PSD decoder on 32-bit builds, causing an infinite loop and denial of service. This issue is fixed in versions 7.1.2-32 and 6.9.13-57.","cveId":"CVE-2026-106567","cvssScore":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-196","CWE-835"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/ImageMagick/ImageMagick/commit/f053f778409932d55b95758c4b1516b63191d1eb","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-g6p6-3ggg-3w7j","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick6/commit/61024a2677a3c7973a2dd27170877d8e51419473","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-57","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00402,"epssPercentile":0.32321,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T16:17:40.973Z","addedAt":"2026-10-07T16:39:32.561Z","updatedAt":"2026-10-08T21:05:41.955Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106567","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106567","note":"authoritative record"}]},{"id":"9ed381de-4a65-42f0-8b03-f9f910f7f038","slug":"cve-2026-106565","externalId":"CVE-2026-106565","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106565 — ImageMagick is free and open-source software used for editing and manipulating digital images.","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a missing end-of-file check while reading bzip2-compressed image data can cause an infinite loop and exhaust processing resources. This issue is fixed in versions 7.1.2-32 and 6.9.13-57.","cveId":"CVE-2026-106565","cvssScore":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-400","CWE-835"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/ImageMagick/ImageMagick/commit/e9872c4a165d869e75d10799c47195725ebf4132","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-m9c7-gf3j-hx6h","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick6/commit/82f752927a552cbba1213b1d023b85e76845774c","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-57","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00402,"epssPercentile":0.32321,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T16:17:40.627Z","addedAt":"2026-10-07T16:39:32.547Z","updatedAt":"2026-10-08T21:05:41.916Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106565","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106565","note":"authoritative record"}]},{"id":"e174f23e-4c64-4690-beb9-39ecc1aee014","slug":"cve-2026-107168","externalId":"CVE-2026-107168","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107168 — A flaw was found in m17n-lib.","description":"A flaw was found in m17n-lib. By providing crafted input containing an invalid UTF-8 character sequence, an attacker can cause the text parsing function to enter an infinite loop. This issue leads to sustained high CPU utilization, resulting in a Denial of Service (DoS) for the affected application.","cveId":"CVE-2026-107168","cvssScore":6.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-835"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-107168","type":"advisory","title":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2547409","type":"advisory","title":"secalert@redhat.com"}],"epssScore":0.00112,"epssPercentile":0.0129,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T13:17:20.183Z","addedAt":"2026-10-07T14:39:35.118Z","updatedAt":"2026-10-07T16:39:32.149Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107168","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107168","note":"authoritative record"}]},{"id":"0ce5814a-54ca-4d64-872a-a2c97a57671f","slug":"cve-2026-104633","externalId":"CVE-2026-104633","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-104633 — When migrating a repository from another Gitea instance, Gitea used the page size reported in the source server's API settings to end its paginated…","description":"When migrating a repository from another Gitea instance, Gitea used the page size reported in the source server's API settings to end its paginated downloads. A source that reported `max_response_items` as `0` made these loops run indefinitely and grow server memory until it was exhausted. Any user who can migrate repositories could point a migration at a server they control and cause a denial of service.","cveId":"CVE-2026-104633","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-400","CWE-835"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.gitea.com/release-of-28.1.0/","type":"advisory","title":"88ee5874-cf24-4952-aea0-31affedb7ff2"},{"url":"https://github.com/go-gitea/gitea/pull/39501","type":"advisory","title":"88ee5874-cf24-4952-aea0-31affedb7ff2"},{"url":"https://github.com/go-gitea/gitea/pull/39507","type":"advisory","title":"88ee5874-cf24-4952-aea0-31affedb7ff2"},{"url":"https://github.com/go-gitea/gitea/releases/tag/v28.1.0","type":"advisory","title":"88ee5874-cf24-4952-aea0-31affedb7ff2"},{"url":"https://github.com/go-gitea/gitea/security/advisories/GHSA-jj5r-9rpc-8h6h","type":"advisory","title":"88ee5874-cf24-4952-aea0-31affedb7ff2"}],"epssScore":0.00388,"epssPercentile":0.30824,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T22:17:01.200Z","addedAt":"2026-10-06T22:39:33.144Z","updatedAt":"2026-10-07T16:39:31.349Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104633","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104633","note":"authoritative record"}]},{"id":"868530bb-89db-4d17-a46b-e1ed59b96096","slug":"cve-2026-106121","externalId":"CVE-2026-106121","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106121 — The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes.","description":"The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.37.0, com.rabbitmq.tools.json.JSONReader.read() fails to terminate when input ends inside a quoted string or a line comment because its string and whitespace scanners do not stop at CharacterIterator.DONE. The default DefaultJsonRpcMapper passes JSON-RPC message bodies to this parser for JsonRpcServer and client replies. A truncated string causes the parser to append replacement end markers until heap exhaustion, while a line comment without a terminating newline can keep a thread consuming CPU indefinitely, resulting in denial of service. This issue is fixed in version 5.37.0.","cveId":"CVE-2026-106121","cvssScore":4.9,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":"Maven","product":"com.rabbitmq:amqp-client","affectedVersions":["pkg:maven/com.rabbitmq/amqp-client < 5.36.1"],"cwes":["CWE-835"],"tags":["nvd","status:awaiting-analysis","osv","osv:ghsa-cqgh-8p3p-mx4m","ecosystem:maven"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/rabbitmq/rabbitmq-java-client/commit/25fad817291feff3195c32620117d295598f8b41","type":"other","title":"OSV web"},{"url":"https://github.com/rabbitmq/rabbitmq-java-client/pull/2100","type":"other","title":"OSV web"},{"url":"https://github.com/rabbitmq/rabbitmq-java-client/releases/tag/v5.37.0","type":"other","title":"OSV web"},{"url":"https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-cqgh-8p3p-mx4m","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-cqgh-8p3p-mx4m","type":"advisory","title":"OSV GHSA-cqgh-8p3p-mx4m"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106121","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/rabbitmq/rabbitmq-java-client","type":"vendor","title":"OSV package"}],"epssScore":0.00493,"epssPercentile":0.40388,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:17:43.193Z","addedAt":"2026-10-06T20:39:30.422Z","updatedAt":"2026-10-08T00:42:49.383Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106121","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106121","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-CQGH-8P3P-MX4M"}]},{"id":"2ecea3b8-71a7-4ba1-ae60-b24f0dacec45","slug":"cve-2026-88252","externalId":"CVE-2026-88252","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-88252 — A flaw was found in sssd.","description":"A flaw was found in sssd. A local user can cause a Denial of Service (DoS) by exhausting the responder service's available file descriptors (system handles used for open connections). By opening and maintaining many concurrent connections to a responder socket while continuing to queue new connection attempts, an attacker can trigger an unthrottled retry loop. This condition leads to high CPU utilization and stalls the service, preventing legitimate identity and authentication requests from being processed.","cveId":"CVE-2026-88252","cvssScore":4.7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-835"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-88252","type":"advisory","title":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2479240","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epssScore":0.00143,"epssPercentile":0.03142,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T18:16:56.867Z","addedAt":"2026-10-06T18:39:27.650Z","updatedAt":"2026-10-06T20:39:30.304Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88252","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-88252","note":"authoritative record"}]},{"id":"c418fb29-945b-417b-82b4-d3431094eb67","slug":"cve-2026-106116","externalId":"CVE-2026-106116","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106116 — ImageSharp is a 2D graphics library.","description":"ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, ExifReader.ReadValues64 trusts the 64-bit BigTIFF IFD entry count and iterates once per declared entry. When fewer than 20 bytes remain, ExifReader.ReadValue64 returns without advancing the stream or terminating the outer loop, so a small malformed BigTIFF can keep one decoder thread executing for an attacker-controlled duration. This report does not claim worker-pool exhaustion. This issue is fixed in version 4.1.2.","cveId":"CVE-2026-106116","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-835"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/SixLabors/ImageSharp/commit/92b12d72550ebb6be5b1e22e559c361fd863a6ec","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/SixLabors/ImageSharp/pull/3187","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/SixLabors/ImageSharp/releases/tag/v4.1.2","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-wmxv-xphr-5c9g","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epssScore":0.00366,"epssPercentile":0.28364,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T18:16:53.400Z","addedAt":"2026-10-06T18:39:27.613Z","updatedAt":"2026-10-06T20:39:30.275Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106116","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106116","note":"authoritative record"}]},{"id":"4ff5afea-73c6-4467-bf09-6881445164a1","slug":"ghsa-6w6g-hm98-mhgm","externalId":"GHSA-6w6g-hm98-mhgm","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"hickory-resolver: Unbounded TC-retry loop in `NameServerPool::try_send` (resource-exhaustion DoS)","description":"When the `hickory-resolver` name server pool implementation receives an upstream response with the TC (truncated) header bit set, it re-queues the request to the same nameserver to retry with UDP transport disabled. However, the retry arm never inspects the transport that just answered and carries no iteration counter. An authoritative server that sets `TC=1` on **every** available transport  keeps the resolver spinning on one persistent TCP connection until the 5s per-request wall-clock deadline expires.\n\n### Reporter\n\nQifan Zhang, Palo Alto Networks","cveId":null,"cvssScore":null,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","severity":"high","vendor":"crates.io","product":"hickory-resolver","affectedVersions":["pkg:cargo/hickory-resolver >= 0.26.0-beta.1, < 0.26.2"],"cwes":["CWE-400","CWE-406","CWE-835"],"tags":["osv","osv:ghsa-6w6g-hm98-mhgm","ecosystem:crates.io"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-6w6g-hm98-mhgm","type":"advisory","title":"OSV GHSA-6w6g-hm98-mhgm"},{"url":"https://github.com/hickory-dns/hickory-dns/security/advisories/GHSA-6w6g-hm98-mhgm","type":"other","title":"OSV web"},{"url":"https://github.com/hickory-dns/hickory-dns/pull/3871","type":"other","title":"OSV web"},{"url":"https://github.com/hickory-dns/hickory-dns/commit/0848d2e9e4183499343318a690d6dd5e48bc21c1","type":"other","title":"OSV web"},{"url":"https://github.com/hickory-dns/hickory-dns/commit/5d37e2e04a36a87013a213b58b820345ef76a263","type":"other","title":"OSV web"},{"url":"https://github.com/hickory-dns/hickory-dns","type":"vendor","title":"OSV package"},{"url":"https://github.com/hickory-dns/hickory-dns/releases/tag/v0.26.2","type":"other","title":"OSV web"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T22:55:10.000Z","addedAt":"2026-10-06T01:54:27.189Z","updatedAt":"2026-10-06T01:54:27.189Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-6w6g-hm98-mhgm"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-6w6g-hm98-mhgm"}]},{"id":"1bcb943f-a8ea-4a81-9e88-6c28e020e799","slug":"ghsa-35mr-4567-66vg","externalId":"GHSA-35mr-4567-66vg","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"Dulwich: Infinite Loop Denial of Service (DoS) in Packfile Object Resolution","description":"### Affected file\n* `dulwich/pack.py` (Method: `Pack.resolve_object`)\n\n### Description / Summary\nA High-severity Denial of Service (DoS) vulnerability exists in the `Pack.resolve_object` method. When resolving an `OFS_DELTA` object, the resolver calculates the base offset using `base_offset = obj_offset - delta_offset`.\n\nIf a malicious packfile contains an `OFS_DELTA` object where `delta_offset` is `0`, the calculation `obj_offset - 0` resolves back to the current object's own offset. Because the implementation lacks a depth counter, a \"visited\" set, or an explicit rejection of `delta_offset == 0`, the resolver enters an infinite recursive loop, exhausting CPU resources and eventually crashing the process.\n\n**Vulnerable Code Breakdown (`dulwich/pack.py`):**\n```python\nelif obj_type == OFS_DELTA:\n    delta_offset = parse_pack_object_offset_at(...)\n    base_offset = obj_offset - delta_offset          # VULNERABILITY: Self-reference if delta_offset == 0\n    base_type, base_data = self.resolve_object(...)  # VULNERABILITY: Infinite recursion\n```\n\n### Potential impact\n\nAn attacker can trigger this infinite loop via any operation that walks packfiles (e.g., `dulwich clone`, `fetch`, `cat-file`, or internal `Pack.__getitem__` lookups). \n\n1. **CPU Exhaustion:** The process will spin at 100% CPU indefinitely.\n2. **Denial of Service:** Any service using `dulwich` (web interfaces, CI/CD runners) will hang or crash, preventing legitimate repository access.\n3. **Protocol Incompatibility:** This behavior violates the Git packfile specification. The standard `git` C client explicitly guards against this: `if (!base_offset) die(\"delta offset == 0 is invalid\");`.\n\n### POC (Proof of Concept)\nThe following Python script generates a 44-byte packfile that triggers the loop:\n\n```python\nfrom dulwich.pack import Pack\nimport struct, zlib, tempfile, os\n\n# Build a single OFS_DELTA entry whose delta_offset is 0\ntype_ofs_delta = 6\nheader = bytes([(type_ofs_delta << 4) | 0])\nofs_bytes = bytes([0x00]) # delta_offset = 0\nbody = zlib.compress(b'')\nraw = header + ofs_bytes + body\n\npack = b'PACK' + struct.pack('>I', 2) + struct.pack('>I', 1) + raw + (b'\\x00' * 20)\n\nfd, path = tempfile.mkstemp(suffix='.pack')\nos.write(fd, pack); os.close(fd)\n\n# Trigger: This call never returns and spins at 100% CPU\np = Pack(path)\nobj = p[list(p.iterobjects())[0]]\n```\n\n### Possible solution\n1. **Explicit Guard:** Add a check in `Pack.resolve_object` to reject `delta_offset == 0`:\n   ```python\n   if delta_offset == 0:\n       raise CorruptPacksFile(\"OFS_DELTA has self-referential delta_offset=0\")\n   ```\n2. **Recursion Depth:** Implement a depth limit (e.g., `MAX_DELTA_DEPTH = 50`) to prevent long, non-looping chains of deltas (OFS or REF).","cveId":null,"cvssScore":null,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","severity":"medium","vendor":"PyPI","product":"dulwich","affectedVersions":["pkg:pypi/dulwich < 1.2.9"],"cwes":["CWE-835"],"tags":["osv","osv:ghsa-35mr-4567-66vg","ecosystem:pypi"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-35mr-4567-66vg","type":"advisory","title":"OSV GHSA-35mr-4567-66vg"},{"url":"https://github.com/jelmer/dulwich/security/advisories/GHSA-35mr-4567-66vg","type":"other","title":"OSV web"},{"url":"https://github.com/jelmer/dulwich/commit/d06ffc3e1aff0ea0a32094debead891be0083eb7","type":"other","title":"OSV web"},{"url":"https://github.com/jelmer/dulwich","type":"vendor","title":"OSV package"},{"url":"https://github.com/jelmer/dulwich/releases/tag/dulwich-1.2.9","type":"other","title":"OSV web"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T18:54:39.000Z","addedAt":"2026-10-02T19:54:22.653Z","updatedAt":"2026-10-02T19:54:22.653Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-35mr-4567-66vg"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-35mr-4567-66vg"}]},{"id":"d49394bc-ad27-4e39-a074-a83d996b0a17","slug":"cve-2026-94654","externalId":"CVE-2026-94654","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-94654 — Loop with unreachable exit condition ('infinite loop') vulnerability in Apache Thrift python bindings.","description":"Loop with unreachable exit condition ('infinite loop') vulnerability in Apache Thrift python bindings.\n\n\n\nThis issue affects Apache Thrift: before 0.25.0.\n\n\n\nUsers are recommended to upgrade to version 0.25.0, which fixes the issue.","cveId":"CVE-2026-94654","cvssScore":8.2,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-835"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1","type":"advisory","title":"security@apache.org"},{"url":"https://lists.apache.org/thread/kx3xdttoypl8j4dcxmqbq9dwy1w0kr7j","type":"advisory","title":"security@apache.org"}],"epssScore":0.00413,"epssPercentile":0.33586,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T13:18:01.987Z","addedAt":"2026-10-02T13:50:40.982Z","updatedAt":"2026-10-02T19:50:41.448Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94654","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-94654","note":"authoritative record"}]},{"id":"83c3cb53-fce1-4060-bbd1-06de60afc096","slug":"cve-2026-85476","externalId":"CVE-2026-85476","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-85476 — Loop with unreachable exit condition ('infinite loop') vulnerability in Apache Thrift c_glib bindings.","description":"Loop with unreachable exit condition ('infinite loop') vulnerability in Apache Thrift c_glib bindings.\n\n\n\nThis issue affects Apache Thrift: before 0.25.0.\n\n\n\nUsers are recommended to upgrade to version 0.25.0, which fixes the issue.","cveId":"CVE-2026-85476","cvssScore":8.2,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-835"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/1zdvscq7p3hf3z30s26h4tm9dvljm1jj","type":"advisory","title":"security@apache.org"},{"url":"https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1","type":"advisory","title":"security@apache.org"}],"epssScore":0.00413,"epssPercentile":0.33586,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T13:17:59.290Z","addedAt":"2026-10-02T13:50:40.978Z","updatedAt":"2026-10-02T19:50:41.440Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85476","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-85476","note":"authoritative record"}]},{"id":"31630fcc-81b0-4123-82f2-07c896f19b7d","slug":"cve-2026-86537","externalId":"CVE-2026-86537","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-86537 — Uncaught exception, Loop with unreachable exit condition ('infinite loop'), Integer underflow (wrap or wraparound) vulnerability in Apache Thrift D…","description":"Uncaught exception, Loop with unreachable exit condition ('infinite loop'), Integer underflow (wrap or wraparound) vulnerability in Apache Thrift D language bindings.\n\n\n\nThis issue affects Apache Thrift: before 0.25.0.\n\n\n\nUsers are recommended to upgrade to version 0.25.0, which fixes the issue.","cveId":"CVE-2026-86537","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-191","CWE-248","CWE-835"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1","type":"advisory","title":"security@apache.org"},{"url":"https://lists.apache.org/thread/k14jfr1xwc0vtmm2s7xro6lt7q4y6s7m","type":"advisory","title":"security@apache.org"}],"epssScore":0.00553,"epssPercentile":0.44426,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T12:17:22.233Z","addedAt":"2026-10-02T13:50:40.793Z","updatedAt":"2026-10-02T15:50:40.918Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86537","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-86537","note":"authoritative record"}]},{"id":"0fc0ac6a-c5ae-42d0-8f9f-a764a11874c5","slug":"cve-2026-86535","externalId":"CVE-2026-86535","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-86535 — Loop with unreachable exit condition ('infinite loop'), Improperly controlled modification of object prototype attributes ('prototype pollution') v…","description":"Loop with unreachable exit condition ('infinite loop'), Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift NodeJS bindings with TJSONProtocol.\n\n\n\nThis issue affects Apache Thrift: before 0.25.0.\n\n\n\nUsers are recommended to upgrade to version 0.25.0, which fixes the issue.","cveId":"CVE-2026-86535","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-835","CWE-1321"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1","type":"advisory","title":"security@apache.org"},{"url":"https://lists.apache.org/thread/94cvvzzl0rh707bn2j4zt844v547508g","type":"advisory","title":"security@apache.org"}],"epssScore":0.0034,"epssPercentile":0.25369,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T12:17:21.960Z","addedAt":"2026-10-02T13:50:40.782Z","updatedAt":"2026-10-02T19:50:41.383Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86535","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-86535","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":195,"totalPages":10,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-09T00:01:40.697Z","durationMs":47,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-835"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}